
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
rollup-plugin-commonjs-alternate
Advanced tools
Alternative CommonJS plugin for Rollup. The standard rollup-plugin-commonjs works very well, but has a few issues:
It doesn't support conditional requires. This means that both development and production versions of libraries will be both included. This plugin does a simple static check to see if the require
call should be included as an import.
It doesn't check for require
calls inside ESM files. This doesn't seem like an issue at first, but it's an issue when using libraries such as React Hot Loader which uses a Babel plugin to inject itself into ESM modules.
It stubs dynamic requires. This is a problem because dynamic requires are necessary for features such as Hot Module Replacement.
This aim of this plugin is to support popular front-end libraries that follow best practices and get them working correctly with HMR. It will remove static analyzable conditional imports, it will check for require calls everywhere, and it won't stub anything it shouldn't.
This plugin will most likely not work libraries that go against best practice (for example, setting a variable to module.exports and adding exports to that).
Static conditional checking doesn't work for libraries like React Hot Loader. You need to either configure an alias or remove it from your production configuration.
It will always assume CJS modules are in strict mode.
Named Exports will not work unless you set it in the plugin configuration. This is just a limitation of using module.exports
and default exports:
let React = {
createElement: ...
createRef: ...
};
module.exports = React;
// equivalent
export default React;
In this example, there's no way to tell what React
is from the module.exports
assignment and what properties it contains. The safest thing we can do is assume it's a default export and assign it to the default key. To access named exports, it has to be explicitly configured.
Object namedExports - Specify what exports files provide. This allows you to use import named exports instead of being forced to use default imports.
commonjs({
namedExports: {
'node_modules/react/index.js': [
'Component',
'createElement'
]
}
})
Array<String> extensions - Specify the extensions of modules that this plugin will transform. Default ['.js']
.
commonjs({
extensions: ['.js', '.jsx']
})
Object<String, String> define - Specify string replacements.
commonjs({
define: {
'process.env.NODE_ENV': JSON.stringify(process.env.NODE_ENV),
'__DEBUG__': JSON.stringify(true)
}
})
FAQs
Alternative CommonJS Rollup plugin.
We found that rollup-plugin-commonjs-alternate demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.