Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Behaviors and access to Retold stuff in the browser.
Uses browserify to generate dist/pict.* and such from node modules.
Currently relies on Fable-Settings but may change.
gulp minified
gulp debug
(or)
gulp build
There is a main controller, the PICT Controller, which handles brokerage between the data sources and the view data.
Eventually we will want to add a mechanism for persisting ViewData and ViewConfig pairs, as well as in isolate. We've used the term Project to describe these, but, it is so generic and we already use that term elsewhere in the HeadLight ecosystem.
+-----------------------+
| |
+--------->+ Pict Controller +<--------+
| | | |
| +-----------------------+ |
| |
| |
| |
+-------+--------+ +-------+------+ | | | | | DataSource | | ViewData +--------------------->+ | | | | | +----------------+ +--------------+ | ^ | | | | | | | | | | | | | +----------------+ +---------+--------+ | | | | | ViewConfig +---------->+ View | | | | | +----------------+ +---------+--------+ | | | | | +--------+--------+ | | | View Renderer | | | +-----------------+
If when you try to gulp build
or gulp debug
you get the following error:
Error: Node Sass does not yet support your current environment: OS X 64-bit with Unsupported runtime (93)
You can run this simple command to fix it:
npm rebuild node-sass
FAQs
Pict browser library.
The npm package pict receives a total of 97 weekly downloads. As such, pict popularity was classified as not popular.
We found that pict demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.