
Research
5 Malicious Chrome Extensions Enable Session Hijacking in Enterprise HR and ERP Systems
Five coordinated Chrome extensions enable session hijacking and block security controls across enterprise HR and ERP platforms.
pear-messages
Advanced tools
Receive object messages from a Pear application's processes/threads using object pattern-matching
Receive object messages from a Pear application's processes/threads using object pattern-matching
import messages from 'pear-messages'
const stream = messages({ some: 'props' })
stream.once('data', console.log)
Elsewhere in app use pear-message:
import message from 'pear-message'
await message({ some: 'props', to: { pattern: ['match', 'against'] } })
Should log: { some: 'props', to: {pattern: ['match', 'against'] }}
messages(pattern[, listener]) -> stream | messages(listener, pattern) -> streamListen for application messages sent with pear-message based on pattern which is an object whose properties match a subset of the properties for a given target message.
A function which accepts a pattern object and returns an Iambus subscriber (which inherits from streamx Readable) which emits message objects matching a provided pattern object.
If no pattern object or an empty pattern object is provided all messages will be emitted. A pattern object is an object (typically) containing a subset of matching values for a given target object. Message objects can be user generated or platform generated.
The subscriber stream has a data event which can be listened to, it can also be consumed with for await and an listener function can be passed in addition to pattern (message(pattern, listener)) or as a single argument (messages(listener)) (indicating a catch-all pattern).
A message object may have any properties. Platform-generated messages are given a type property.
The message stream is auto-ended during Pear.teardown.
Listen for an internal platform message using a pattern object and listener function:
import messages from 'pear-messages'
messages({ type: 'pear/wakeup' }, ({ data, link }) => {
console.log('pear/wakeup', data, link)
})
Tiny utility module which logs all messages using for await:
import messages from 'pear-messages'
for await (const message of messages()) {
if (global.LOGBUS) console.log('BUS:', message)
}
Use message to create an application message:
import message from 'pear-message'
import messages from 'pear-messages'
const ctaClicks = messages({ type: 'my-app/user-cta' })
ctaClicks.on('data', (msg) => {
console.log('cta click', msg)
})
// elsewhere
onUserClickCta((event, data) => {
message({ type: 'my-app/user-cta', event, data })
})
Apache-2.0
FAQs
Receive object messages from a Pear application's processes/threads using object pattern-matching
The npm package pear-messages receives a total of 511 weekly downloads. As such, pear-messages popularity was classified as not popular.
We found that pear-messages demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Five coordinated Chrome extensions enable session hijacking and block security controls across enterprise HR and ERP platforms.

Research
Node.js patched a crash bug where AsyncLocalStorage could cause stack overflows to bypass error handlers and terminate production servers.

Research
/Security News
A malicious Chrome extension steals newly created MEXC API keys, exfiltrates them to Telegram, and enables full account takeover with trading and withdrawal rights.