
Security News
OpenClaw Skill Marketplace Emerges as Active Malware Vector
Security researchers report widespread abuse of OpenClaw skills to deliver info-stealing malware, exposing a new supply chain risk as agent ecosystems scale.
node-carplay
Advanced tools
Node Carplay npm package

This is a carplay module for nodejs. It is currently in development, but is at a useable stage. Currently it interacts with a Carlinkit adapter, it opens communication with it, sends various configuration settings and also downloads the APK file thats usually used with it. The APK file then gets extracted and its contents get sent over usb to the dongle itself. The dongle then sends a h264 bytestream from the phone, this contains the video data. And it also sends an audio stream.
This project would not of been possible without electric monks work on a python version. It also heavily uses node-usb jsmpeg player
The target machine should have FFMPEG/FFPLAY installed and working
npm install node-carplay
TODO see react-carplay
Contributions are what make the open source community such an amazing place to be learn, inspire, and create. Any contributions you make are greatly appreciated.
git checkout -b feature/AmazingFeature)git commit -m 'Add some AmazingFeature')git push origin feature/AmazingFeature)Your Name - Rhys Morgan - rhysm134@gmail.com
FAQs
Carplay dongle driver for Node.js & Browser
The npm package node-carplay receives a total of 6 weekly downloads. As such, node-carplay popularity was classified as not popular.
We found that node-carplay demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Security researchers report widespread abuse of OpenClaw skills to deliver info-stealing malware, exposing a new supply chain risk as agent ecosystems scale.

Security News
Claude Opus 4.6 has uncovered more than 500 open source vulnerabilities, raising new considerations for disclosure, triage, and patching at scale.

Research
/Security News
Malicious dYdX client packages were published to npm and PyPI after a maintainer compromise, enabling wallet credential theft and remote code execution.