Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
this package is meant mostly for myself.
[API]https://paka.dev/npm/pastable@2.0.13/api
pnpm i pastable
With 1 main & 5 specific entrypoints:
"pastable"
: re-exports everything from utils+typings"pastable/utils"
"pastable/react"
"pastable/typings"
"pastable/machines"
"pastable/server"
everything that's commonly used server-side (= no browser APIs + no vendors like react/xstate)import { useSelection } from "pastable";
// or
import { useSelection } from "pastable/react";
In every project I've been a part of, I've always ended up copy/pasting some part of a previous project that I had made generic, and moving from one project to another I just kept pasting it over and over.
So here we are, I made yet another multi-purpose-utils package !
It aims to be as generic as possible so that either the source can litteraly be pasted if you just need a couple of functions or you can install any specific package at some point.
100% written in Typescript, near 100% code coverage as a constant goal.
Feel free to contribute if you think there is space for one of your previous projects gems.
Packages are built with https://preconstruct.tools/ & tested with https://vitest.dev/, special thanks to their authors for those priceless gems !
@
alias to simplify the publish process, replaced uvu by vitestFAQs
📦 A collection of pastable code gathered from past projects
We found that pastable demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.