
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
A simple VIN (Vehicle Identification Number) checker. All checks based on ISO 3779:2009. Detailed info: https://en.wikipedia.org/wiki/Vehicle_identification_number
This module contains only a part (about 1000) WMI-code the major vehicle manufacturers. The complete SAE WMI database contains more than 33,000 international WMI codes and is available through annual subscription to the site http://www.sae.org/standardsdev/groundvehicle/vin.htm
Starting with version 2.1.0, added all the codes xUSSR manufacturers.
Install from npm:
$ npm install vin-lite
Some manufacturers realized an algorithm that decrypts the additional information about the car from the VIN code. Additional information is now extracted for
To retrieve additional information transmitted by the second argument when you call vin.decode method
var vin = require('vin-lite');
console.log(vin.isValid("WVWZZZ3CZEE140287")); // true
console.log(vin.isValid("WVWZZZ3CZEE140287",false)); // Verify regular expression only
console.log(vin.decode("WVWZZZ3CZEE140287",true));
/* { wmi: 'WVW',
vds: 'ZZZ3CZ',
vis: 'EE140287',
sequentialNumber: '140287',
check: 'Z',
continent: 'Europe',
country: 'West Germany',
manufacturer: 'Volkswagen',
modelYear: 2014,
manufacturerInfo: { description: 'Passat 7, Passat CC', place: 'Emden, Germany' } }
*/
USA Check digit validate. This test can be applied to cars, which were produced to the USA market
console.log(vin.USAValidate("YV1TS592861433393")); // true
FAQs
VIN (Vehicle Identification Number) Checker Lite
The npm package vin-lite receives a total of 289 weekly downloads. As such, vin-lite popularity was classified as not popular.
We found that vin-lite demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.