
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
super-simple-web-server
Advanced tools
A super simple node-express web server with https option for when you quickly need to serve some static files. Package includes self-signed certificates. Don't use this for production.
Serve static files on localhost with http & https.
npm install super-simple-web-server
Clone repo and run npm install
in the root directory.
npm start [</path/to/web/root>]
###Default path Default path is your current working directory. Override by passing an optional path to your desired web root directory.
###Default ports
Default ports are 3000
(http) and 3001
(https). These can be changed in index.js
.
###Default IP
The default IP 127.0.0.1
which should convieniently map to localhost
.
Pro tip: Setting USE_LOCALHOST = false
in index.js
will instead scan for existing bound IP addresses on your machine via os.networkInterfaces()
. The last available will be used.
Fictious self-signed certs are provided for your development convienience. They will exprire on June 6 2028. Obviously -- you don't want to use these for anything other than private testing.
See ./certs/
for more info...
FAQs
A super simple node-express web server with https option for when you quickly need to serve some static files. Package includes self-signed certificates. Don't use this for production.
The npm package super-simple-web-server receives a total of 32,841 weekly downloads. As such, super-simple-web-server popularity was classified as popular.
We found that super-simple-web-server demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.