Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
github.com/rs/xstats
Package xstats
is a generic client for service instrumentation.
xstats
is inspired from Go-kit's metrics package but it takes a slightly different path. Instead of having to create an instance for each metric, xstats
use a single instance to log every metrics you want. This reduces the boiler plate when you have a lot a metrics in your app. It's also easier in term of dependency injection.
Talking about dependency injection, xstats
comes with a xhandler.Handler integration so it can automatically inject the xstats
client within the net/context
of each request. Each request's xstats
instance have its own tags storage ; This let you inject some per request contextual tags to be included with all observations sent within the lifespan of the request.
xstats
is pluggable and comes with integration for expvar
, StatsD
and DogStatsD
, the Datadog augmented version of StatsD with support for tags. More integration may come later (PR welcome).
go get github.com/rs/xstats
// Defines interval between flushes to statsd server
flushInterval := 5 * time.Second
// Connection to the statsd server
statsdWriter, err := net.Dial("udp", "127.0.0.1:8126")
if err != nil {
log.Fatal(err)
}
// Create the stats client
s := xstats.New(dogstatsd.New(statsdWriter, flushInterval))
// Global tags sent with all metrics (only with supported clients like datadog's)
s.AddTags("role:my-service", "dc:sv6")
// Send some observations
s.Count("requests", 1, "tag")
s.Timing("something", 5*time.Millisecond, "tag")
Integration with github.com/rs/xhandler:
var xh xhandler.HandlerC
// Here is your handler
xh = http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
// Get the xstats request's instance from the context. You can safely assume it will
// be always there, if the handler is removed, xstats.FromContext will return a nop
// instance.
m := xstats.FromRequest(r)
// Count something
m.Count("requests", 1, "route:index")
})
// Install the metric handler with dogstatsd backend client and some env tags
flushInterval := 5 * time.Second
tags := []string{"role:my-service"}
statsdWriter, err := net.Dial("udp", "127.0.0.1:8126")
if err != nil {
log.Fatal(err)
}
xh = xstats.NewHandler(dogstatsd.New(statsdWriter, flushInterval), tags, xh)
// Root context
ctx := context.Background()
h := xhandler.New(ctx, xh)
http.Handle("/", h)
if err := http.ListenAndServe(":8080", nil); err != nil {
log.Fatal(err)
}
func TestFunc(t *testing.T) {
m := mock.New()
s := xstats.New(m)
m.On("Timing", "something", 5*time.Millisecond, "tag")
s.Timing("something", 5*time.Millisecond, "tag")
s.AssertExpectations(t)
}
All source code is licensed under the MIT License.
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.