Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
github.com/hashintel/hash
This is HASH's public monorepo which contains our public code, docs, and other key resources.
HASH is a self-buliding, open-source database which grows, structures and checks itself. With it, we're creating a platform for decision-making, which helps you integrate, understand and use data in a variety of different ways. Read our blog post →
Coming soon: we'll be collecting examples in the Awesome HASH repository.
Browse the HASH development roadmap for more information about currently in-flight and upcoming features.
This repository's contents is divided across several primary sections:
/apps
contains the primary code powering our runnable applications/blocks
contains our public Block Protocol blocks/infra
houses deployment scripts, utilities and other infrastructure useful in running our apps/libs
contains libraries including npm packages and Rust crates/tests
contains end-to-end and integration tests that span across one or more apps, blocks or libsPlease see CONTRIBUTING if you're interested in getting involved in the design or development of HASH.
We're also hiring for a number of key roles. If you contribute to HASH's public monorepo be sure to mention this in your application.
The vast majority of this repository is published as free, open-source software. Please see LICENSE for more information about the specific licenses under which the different parts are available.
Please see SECURITY for instructions around reporting issues, and details of which package versions we actively support.
Find us on 𝕏 at @hashintel, email hey@hash.ai, or join our Discord forum for quick help and community support.
Project permalink: https://github.com/hashintel/hash
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.