
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
stb-devtools
Advanced tools
STB Devtools is a suite of tools built on top of websockets to a backend from a JS environment
Tools written in plain Javascript to setup some tools to help work on devices without Webdriver support.
Due to usage of WeakSet for circular JSON detection the browser support is defined fully here: https://caniuse.com/?search=Weakset
Native Browser Support:
Put a <script> tag into your application's HTML that loads client/index.js. This will put the following APIs into the global scope.
createSocket('ws://localhost:3031') Creates a websocket connection to the remote server provided, other features work over this network connection.closeSocket() Closes the websocket connection on the client.API:
injectConsole() Replaces the console API with sending logs to the socket server.restoreConsole() Restores the console API back to it's original methods.API:
remoteControlOn() Starts broadcasting keyboard events from this browser to all other connected clients, who will dispatch the events as synthetic keyboard events locally automatically.From the client send a command like the below
stbSocket.send(JSON.stringify({command: 'temp-file', data: data }));
{
command: 'temp-file',
data: 'stringetc'
}
Will be saved to a temporary file using the module tempy.
FAQs
STB Devtools is a suite of tools built on top of websockets to a backend from a JS environment
The npm package stb-devtools receives a total of 424 weekly downloads. As such, stb-devtools popularity was classified as not popular.
We found that stb-devtools demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.