Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
github.com/reload/dnsimple-dk-hostmaster-ds-upload
[!IMPORTANT] Deprecated: Punktum.dk has closed the DS-update Service, see https://punktum.dk/artikler/breaking-changes
Package function is a Google Cloud Function receiving webhook events from DNSimple (https://dnsimple.com/webhooks).
It reacts to dnssec.rotation_start
and dnssec.rotation_complete
events and passes the new DS record on to Punktum.dk via their DS
Update protocol
(https://github.com/Punktum-dk/dsu-service-specification).
The cloud function needs to be configured through environment variables.
The TOKEN
environment variable is the access token that should be
added as URL query parameter to the trigger URL (e.g.
?token=abcdefeghijklmnopqrstuvxyz0123456789
).
The DNSIMPLE_TOKEN
environment variable is a DNSimple API token that
is used to retrieve DS records from DNsimple.
For the domains in your DNSimple account that you would like this cloud function to update in Punktum.dk you need to add three environment variables. They should all be prefix with the Domain ID from DNSimple (e.g. 123456).
123456_DOMAIN
: the (apex) domain name in Punktum.dk.
123456_USERID
: the Punktum.dk handle you use to login to their
self service.
123456_PASSWORD
: the Punktum.dk password you use to login to
their self service.
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.