
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
react-inliner
Advanced tools
React components rendered and inlined server-side.
Stream HTML in, get React-rendered HTML out and improve the SEO and accessibility of your Web pages!
The module is still in its early days and looks forward to be improved.
npm install --save react-inliner
This Node.js module looks for some `data-react-inliner* attributes within HTML content. It then renders the associated React component and prepends the resulting content into the HTML tag.
<!DOCTYPE html>
<html>
<body>
<h1>My Cool React Single Page App</h1>
<nav data-react-inliner="src/nav.jsx"></nav>
<main data-react-inliner="src/app.js"></main>
</body>
</html>
It uses Streams under the hood so the HTML filesize should not matter much.
Regular read input
react-inliner inputFile.html -o outputFile.html
By piping HTML in.
cat inputFile.html | react-inliner -o outputFile.html
By piping HTML in and out.
cat inputFile.html | react-inliner | htmlhint
Suppress data reconciliation through the data-reactid attribute:
react-inliner inputFile.html -o outputFile.html --no-reactid
Get some help.
react-inliner --help
package.json{
"scripts": {
"build-html": "react-inliner src/index.html -o dist/index.html"
}
}
Then run npm run build-html.
var inliner = require('react-inliner');
fs.createReadStream('src/index.html')
.pipe(inliner({ reactId: false }))
.pipe(fs.createWriteStream('dist/index.html');
Warning: there is an ugly hack preventing *.less files to be processed by the require() function.
So it might create a black hole in your app if you use the module API.
The MIT License (MIT)
Copyright © 2014 Thomas Parisot, https://oncletom.io
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the “Software”), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in
all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
THE SOFTWARE.
FAQs
React components rendered and inlined server-side.
The npm package react-inliner receives a total of 9 weekly downloads. As such, react-inliner popularity was classified as not popular.
We found that react-inliner demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.