
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
CLI tool for developing VTEX apps.
First, install node and npm (Linux, Mac and Windows).
Then install VTEX Toolbelt globally:
npm install -g vtex
Add to your layout the script:
<script src="http://localhost:35729/livereload.js?snipver=1"></script>
To develop an app locally, open the directory where your VTEX app is then type:
vtex watch <sandbox-name>
You are free to set any name you want in the sandbox-name
parameter.
VTEX Toolbelt will upload all your app files to the sandbox specified and will be watching for any changes you make to them.
For this to work make sure this requirements are filled:
meta.json
(read more)meta.json
filevtex_sandbox
cookie (read more)To publish your VTEX app to VTEX Gallery, just type vtex publish
. The app will be published under the vendor name.
FAQs
The platform for e-commerce apps
The npm package vtex receives a total of 1,435 weekly downloads. As such, vtex popularity was classified as popular.
We found that vtex demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 110 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.