
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
Extraction of utility library from https://github.com/mmikowski/hi_score. Version tracks hi_score.
The xuu.js (pronounced "zoo") utility library is a stand-alone port of
the hi_score utility library found in hi_score/js/xhi/01_util.js.
The test suite, nodeunit_xuu.js is extracted from
hi_score/test.d/00_xhi_libs.js.
The version of xuu.js tracks that of hi_score. In other words, version
1.7.11 matches the capabilties and testing of the 1.7.11 of hi_score.
1.7.12 Updates minified version to include 1.7.11 change
1.7.11 Makes timezone check more permissive to include a colon
1.7.10 Adds support for _return_map_ in method _makeTmpltStr_
FAQs
Extraction of utility library from https://github.com/mmikowski/hi_score. Version tracks hi_score.
The npm package xuu receives a total of 7 weekly downloads. As such, xuu popularity was classified as not popular.
We found that xuu demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.