
Research
/Security News
Toptal’s GitHub Organization Hijacked: 10 Malicious Packages Published
Threat actors hijacked Toptal’s GitHub org, publishing npm packages with malicious payloads that steal tokens and attempt to wipe victim systems.
Supply Chain Security
Vulnerability
Quality
Maintenance
License
v8r is a command-line validator that uses Schema Store to detect a suitable schema for your input files based on the filename.
📦 Install the package from NPM
📚 Jump into the Documentation to get started
📦 5.0.0 - 2025-05-10
Following on from the deprecations in version 4.4.0, version 5.0.0 contains a number of breaking changes:
--format
CLI argument and format
config file key have been removed.
Switch to using --output-format
and outputFormat
..gitignore
by default.fileLocation
argument of getSingleResultLogMessage
has been removed.
The signature is now getSingleResultLogMessage(result, format)
.
Plugins implementing the getSingleResultLogMessage
hook will need to to update
the signature.
If you are using fileLocation
in the getSingleResultLogMessage
function body,
switch to using result.fileLocation
.getSingleResultLogMessage
, getAllResultsLogMessage
and parseInputFile
plugin hooks may need to be updated.Other changes in this release:
FAQs
A command-line JSON, YAML and TOML validator that's on your wavelength
The npm package v8r receives a total of 2,753 weekly downloads. As such, v8r popularity was classified as popular.
We found that v8r demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Threat actors hijacked Toptal’s GitHub org, publishing npm packages with malicious payloads that steal tokens and attempt to wipe victim systems.
Research
/Security News
Socket researchers investigate 4 malicious npm and PyPI packages with 56,000+ downloads that install surveillance malware.
Security News
The ongoing npm phishing campaign escalates as attackers hijack the popular 'is' package, embedding malware in multiple versions.