
Research
/Security News
Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader
North Korean threat actors deploy 67 malicious npm packages using the newly discovered XORIndex malware loader.
path
utils for thingsStandalone and stateless imply that this package works without any context, unlike Node's built-in path module
which sometimes will use process.cwd()
to do its thing.
If you didn't pick up already, this package is intended to be used in web apps only. And for that reason code size has been kept as little as possible.
Some differences from node's path
module:
splitPath
exported from this package splits path on each delimeterjoin
, normalize
or relative
removeTrailingSlashes
if you so desirenpm i path-fx
import {
// platform auto-detected utils
dirname, extname, // basename, ...
// platform specific
win32, unix
} from 'path-fx';
// platform auto-detected utils
console.log(dirname('/etc/ping/pong')); // > /etc/ping
console.log(extname('/etc/ping/pong/foo.js')); // > .js
// notice back slash in the output (unix delimits path(s) only on forward slashes)
console.log(unix.basename('/etc/ping/pong/foo\\bar.js')); // > foo\bar.js
// notice mixed slashes (win32 uses forward AND back slashes as folder separators)
console.log(win32.basename('C:\\etc/ping\\pong/foo\\bar.js')); // > bar.js
dist/typings/index.d.ts
This module will use navigator.platform
to set initial path separator it'll use for exported functions.
It is advised that you set it manually with path.setPathSeparator()
to be sure.
Moving from 1.5.1
to 2.0.0
, setPathSeparator
was removed as it was a global operation and was an opportunity for accidental bugs in your codebase.
Instead, 2.0.0+
now exports unix
and win32
objects alongside auto-detected utils.
FAQs
Path utils which don't necessarily depend on Node.js
We found that path-fx demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
North Korean threat actors deploy 67 malicious npm packages using the newly discovered XORIndex malware loader.
Security News
Meet Socket at Black Hat & DEF CON 2025 for 1:1s, insider security talks at Allegiant Stadium, and a private dinner with top minds in software supply chain security.
Security News
CAI is a new open source AI framework that automates penetration testing tasks like scanning and exploitation up to 3,600× faster than humans.