
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
Publican is a tiny, simple, and very fast HTML-first static site generator.
Full documentation is available at Publican.dev.
Features:
${ expression }!{ expression } values are converted to ${ expression } at build time. Templates can be partially-built where possible and used in Express.js or other frameworks with jsTACSIf necessary, create a new Node.js project directory:
mkdir mysite
cd mysite
npm init
Add "type": "module", to package.json to use EcmaScript modules by default.
Install Publican:
npm i publican
Create markdown or other content files in the src/content/ sub-directory. For example, src/content/#index.md:
---
title: My Publican site
---
This is my new static site!
*Under construction!*
Create HTML template files in the src/template/ sub-directory. For example, src/template/default.html:
<!doctype html>
<html>
<head>
<meta charset="UTF-8">
<title>${ data.title }</title>
</head>
<body>
${ include('_partials/header.html') }
<main>
<h1>${ data.title }</h1>
${ data.content }
</main>
</body>
</html>
The template above includes a partial at src/template/_partials/header.html:
<header>
<nav><a href="${ tacs.root }">HOME</a></nav>
</header>
Create a configuration file in the project root, e.g. publican.config.js (use a .mjs extension if "type": "module", is not set in package.json):
import { Publican } from 'publican';
const publican = new Publican();
// clear build directory (optional)
await publican.clean();
// build site
await publican.build();
Build the site to the ./build/ directory:
node publican.config.js
For more information, refer to the full documentation at Publican.dev.
FAQs
Publican is a simple and fast HTML-first static site generator for Node.js
The npm package publican receives a total of 3 weekly downloads. As such, publican popularity was classified as not popular.
We found that publican demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.