
Research
/Security News
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
@realtebo/local-smtp-blackhole
Advanced tools
> IMPORTANT: This package is meant to be used ONLY with composer package `laravel-local-smtp-blackhole`.
IMPORTANT: This package is meant to be used ONLY with composer package
laravel-local-smtp-blackhole.
This package offers a minimal but full working smtp that catches email but doesn't send to recipients. Instead, it save to db to allow later inspection, preview, etc.
Both this and the composer companion package are NOT meant to be used in production.
Every time an email is received, this package fire an event via websocket, so listening clients can not only read email in the db, but be informed realtime of the new message.
This package (and the companion one) is compatible only with mysql.
host/ip: hostname/ip of machine running this code
username: localsmtp
password: blackhole
port: 2525
authmod: normal password, supports but ignores SSL/TLS
We're running a socket.io server on port 2626
npm install @realtebo/local-smtp-blackhole --save-dev [--no-bin-links]
or
yarn add @realtebo/local-smtp-blackhole --dev [--no-bin-links]
node node_modules/@realtebo/local-smtp-blackhole/src/local-smtp-sever.js
This package is not meant to be used alone. It must be used with composer package laravel-local-smtp-blackhole.
The composer package offer a laravel gui to see the email catched by this package.
Until the composer package will be officially released, you can install using github repository. See the companion github repository to instructions.
Never, never, never use this package in production environments !
Feel free to open issues for requests, ideas and what else.
FAQs
> IMPORTANT: This package is meant to be used ONLY with composer package `laravel-local-smtp-blackhole`.
We found that @realtebo/local-smtp-blackhole demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.

Research
/Security News
Docker and Socket have uncovered malicious Checkmarx KICS images and suspicious code extension releases in a broader supply chain compromise.

Product
Stay on top of alert changes with filtered subscriptions, batched summaries, and notification routing built for triage.