
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
Cross-platform PCI info in nodejs.
var pciinfo = require('pciinfo');
pciinfo(function(error, info){
if (error) throw error;
console.log(info);
});
I also included a CLI util. pciinfo will give you a nice JSON list of your PCI devices.
npm install --save pciinfo
If you want pciinfo in your path, do npm install -g pciinfo. Both utils have a --help flag, so you can learn more about how they work.
You will need to install bin/DirectHW.pkg for this to work. It will install DirectHW.kext in your system directory.
You should be good-to-go.
lspci (from pciutils) needs to be in your path.
FAQs
Cross-platform PCI info
We found that pciinfo demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.