
Research
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
retrieve-real-html
Advanced tools
Retrieves the HTML a browser would see after a full page load and scroll to bottom.
A function that retrieves the fully rendered HTML for a given a webpage and outputs it to a file. The function also returns the html string itself for method chaining if needed.
import { retrieveRealHTML } from 'retrieve-real-html';
import path from 'path';
// retrieves HTML from CNN homepage to folder in project root folder under output-images/
async function test() {
const retrieveRealHTML = await retrieveRealHTML(
"https://edition.cnn.com",
path.join(__dirname, "..", "output-html")
);
console.log(
"Done with HTML retrieval. Retrieved HTML: " +
JSON.stringify(retrieveRealHTML)
);
}
test();
FAQs
Retrieves the HTML a browser would see after a full page load and scroll to bottom.
The npm package retrieve-real-html receives a total of 7 weekly downloads. As such, retrieve-real-html popularity was classified as not popular.
We found that retrieve-real-html demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.