
Research
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.
survey-creator-react
Advanced tools
A visual designer that enables you and your users to create and modify surveys and forms in your React application.
Try Survey Creator / Form Builder
To get started with Survey Creator / Form Builder for React, refer to the following tutorial: Add Survey Creator / Form Builder to a React Application.
If you want to build the library yourself, do the following:
Build survey-library and survey-creator-core
Refer to the following instructions:
NOTE: Make sure that folders with cloned
survey-libraryandsurvey-creatorrepositories are in the same directory.
Install build dependencies for Survey Creator / Form Builder for React
cd survey-creator/packages/survey-creator-react
npm install
Build the library
npm run build
You can find the built library in the "build" directory.
Run unit tests
npm test
This command runs unit tests using Karma.
Survey Creator is not available for free commercial usage. If you want to integrate it into your application, you must purchase a commercial license. However, you can use Survey Creator online to produce survey JSON configurations and run them with SurveyJS Form Library in your application free of charge.
FAQs
A white-label drag-and-drop form builder for React that lets you design complex, interactive forms and surveys without writing code. It generates JSON schemas used by the SurveyJS Form Library to render dynamic forms in your React app.
The npm package survey-creator-react receives a total of 79,086 weekly downloads. As such, survey-creator-react popularity was classified as popular.
We found that survey-creator-react demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.