
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
react-shielded
Advanced tools
Add the Women's Refuge Shielded Site button to your React website.
From The Shielded Site Project website:
We’ve created a tool for victims of abuse to ask for help, without fear of it showing up in their browser’s history or an abusive partner ever seeing it. A simple icon which can sit on any website and launch a powerful resource to help end domestic violence.
Install with your favourite package manager:
npm install react-shielded
or yarn add react-shielded
.
:warning: Requires React v16.14.0 or higher.
Import in the Shielded
component:
import Shielded from 'react-shielded';
Use in your React app:
...
<Shielded />
...
And that's it!
v2.1.0 - 2023-03-29
message
event on window
to detect close button clicked in iframe.FAQs
Add the Women's Refuge Shielded Site button to your React website
The npm package react-shielded receives a total of 2,298 weekly downloads. As such, react-shielded popularity was classified as popular.
We found that react-shielded demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.