
Research
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.
rphm_library
Advanced tools
RPHM is a free style library that manages the positioning of HTML elements. This library was created by Raphael BARD, Pierre-Louis BASTIN, and Nassime HARMACH with the aim of improving the web application development process.
npm install rphm_library
Lors de la première installation sur l'ordinateur, il est nécessaire d'exécuter la commande suivante. Vous devez vous trouver dans le dossier racine d'application Angular et taper la commande suivante.
./node_modules/rphm_library/script.sh
Une fois l'étape précédente effectuée, vous pouvez profiter pleinement de la bibliothèque.
Si vous souhaitez installer cette bibliothèque sur un autre projet Angular, vous pouvez reprendre le processus d'installation précédent (npm install) ensuite vous n'avez plus besoin de définir le chemin du fichier script pour le lancer. Il vous suffit d'exécuter la commande suivante à la racine de votre dossier projet.
rphm
FAQs
RPHM is a free style library that manages the positioning of HTML elements. This library was created by Raphael BARD, Pierre-Louis BASTIN, and Nassime HARMACH with the aim of improving the web application development process.
The npm package rphm_library receives a total of 0 weekly downloads. As such, rphm_library popularity was classified as not popular.
We found that rphm_library demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.