
Research
6 Malicious Packagist Themes Ship Trojanized jQuery and FUNNULL Redirect Payloads
Six malicious Packagist packages posing as OphimCMS themes contain trojanized jQuery that exfiltrates URLs, injects ads, and loads FUNNULL-linked redirects.
webflow-api
Advanced tools
Install the package via NPM or YARN:
$ npm install --save webflow-api
$ yarn add webflow-api
Note: this API client is compatible with the browser in addition to Node.js, and thus can be utilized with Webpack or Browserify. However, at this time the beta launch of the API does not support browser clients - that functionality will be released at a later date.
const Webflow = require('webflow-api');
// Initialize the API
const api = new Webflow({ token: 'api-token' });
// Fetch a site
api.site('580e63e98c9a982ac9b8b741').then(site => console.log(site));
The Webflow constructor takes several options to initialize the API client:
token - the API token (required)version - the version of the API you wish to use (optional)All of the API methods are documented in the API documentation.
Contributions are welcome - feel free to open an issue or pull request.
The MIT license - see LICENSE.
FAQs
[](https://www.npmjs.com/package/webflow-api) [](https://github.com/fern-api/fern)
The npm package webflow-api receives a total of 41,170 weekly downloads. As such, webflow-api popularity was classified as popular.
We found that webflow-api demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Six malicious Packagist packages posing as OphimCMS themes contain trojanized jQuery that exfiltrates URLs, injects ads, and loads FUNNULL-linked redirects.

Security News
The GCVE initiative operated by CIRCL has officially opened its publishing ecosystem, letting organizations issue and share vulnerability identifiers without routing through a central authority.

Security News
The project is retiring its odd/even release model in favor of a simpler annual cadence where every major version becomes LTS.