
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
vinted-client
Advanced tools
api-vinted is a package that provides an unofficial API for interacting with the Vinted platform.
⚠️ Warning: This project is currently under development and is not an official package. Use it at your own risk.
npm install vinted-client
const { User } = require("vinted-client");
const user = new User(access_token, refresh_token, x_crf_token);
// Initialize the user
user.init();
// Now you can access to user information
console.log(user.user);
Summary:
await user.getNotifications(page?, per_page?);
Parameters:
page (optional): The page number to get notifications from. Default is 1.per_page (optional): The number of notifications to get per page. Default is 5.await user.getOrders(type, status, page?, per_page?);
Parameters:
type ("sold" | "purchased" | "all"): The type of orders to get. Default is all.status ("all" | "in_progress" | "completed" | "canceled"): The status of orders to get. Default is all.page (optional): The page number to get orders from. Default is 1.per_page (optional): The number of orders to get per page. Default is 5.await user.getStats();
await user.getConversations(conversation_id);
Parameters:
conversation_id (number): The ID of the conversation to get.await user.getInbox(page?, per_page?);
Parameters:
page (optional): The page number to get conversations from. Default is 1.per_page (optional): The number of conversations to get per page. Default is 5.If you have any questions or need further assistance, feel free to contact me on Discord. My tag is .skanix. I'm looking forward to hearing from you!
GPL-3.0
FAQs
An unofficial API for Vinted
We found that vinted-client demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.