
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
github.com/franeklubi/tie
Package franeklubi/tie
provides a Processing-like API for simple and fun drawing,
game making, data and algorithm visualization, and generally - art :)
To install this package:
go get github.com/franeklubi/tie
You'll also need to install dependencies. (see Dependencies)
This package depends on two other packages:
To install these, use:
go get github.com/go-gl/gl/v2.1/gl
then
go get github.com/go-gl/glfw/v3.2/glfw
and You should be all set! :)
Main features:
( For more examples visit franeklubi/tie-examples! )
package main
// import the package
import (
"github.com/franeklubi/tie"
)
func main() {
// initialize engine in main
tie.Init(500, 500, "window_name", false)
// width, height, window_name, is_resizable
// pass all the functions you want used by the engine
tie.PassFunctions(
preload,
setup,
draw,
)
// launch the engine
tie.Launch()
}
var (
img tie.Image
)
// called only once, before setup, nothing can be drawn here
func preload() {
img = tie.LoadImage("/path/to/image.png")
}
// called only once, before draw, you can draw here
func setup() {
tie.Background(255, 255, 255, 255)
}
// called once every frame
func draw() {
// drawing loaded image
tie.Fill(255, 255, 255, 255)
tie.PastePixels(img, 0, 0, tie.Width, tie.Height)
// drawing ellipse
tie.Fill(0, 255, 0, 255)
tie.Ellipse(tie.Width/2, tie.Height/2, 200, 200)
// drawing rectangle
tie.Fill(0, 255, 255, 255)
tie.Rect(tie.Width/2-50, tie.Height/2-50, 100, 100)
}
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.