
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
nitro-cloudflare-dev
Advanced tools
POC module to enable access to the Cloudflare runtime bindings in development server of Nitro and Nuxt
This proof of concept module enables access to the Cloudflare runtime platform in the development server of Nitro and Nuxt using the new getPlatformProxy API exposed by wrangler and miniflare
[!NOTE] Nitro plans to introduce a new method to allow native dev presets, meaning you can natively run miniflare as your development server without this module or a proxy in the future!
First, install nitro-cloudflare-dev and wrangler packages as a dev dependency: (unjs/nypm will automatically detect your package manager!)
npx nypm@latest add -D wrangler nitro-cloudflare-dev
For Nuxt update nuxt.config.ts:
export default defineNuxtConfig({
modules: ["nitro-cloudflare-dev"],
});
For Nitro update nitro.config.ts:
import nitroCloudflareBindings from "nitro-cloudflare-dev";
export default defineNitroConfig({
modules: [nitroCloudflareBindings],
});
This module automatically finds the closest wrangler.toml file for configuration.
Data is persisted .wrangler/state/v3 directory. On first use of the module, it will be automatically added to the .gitignore file.
You can configure additional options using cloudflareDev: { } in nitro.config or nitro: { cloudflareDev: {} } in nuxt.config.
persistDir: Sets the persist dir (default .wrangler/state/v3).configPath: Sets a custom path for wrangler.toml file.silent: Hide initial banner.environment: Sets specific environment (useful for multi-environment configurations)corepack enablepnpm installpnpm build --stubpnpm dev:nitro or Nuxt playground using pnpm dev:nuxtFAQs
POC module to enable access to the Cloudflare runtime bindings in development server of Nitro and Nuxt
We found that nitro-cloudflare-dev demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.