
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@tokenscript/engine-js
Advanced tools
engine-js is a Typescript implementation of the TokenScript runtime. It provides core functionality for resolving, parsing & running TokenScript applications and is the reference implementation used to develop new features for the standard.
The engine is designed as a headless runtime that relies on user-agent interfaces for features such as wallet access and TokenScript card presentations.
In this way the engine is suitable to be used in the browser and server, and can also be integrated as a webview component into native applications.
To demonstrate how to integrate the engine, we provide our reference frontend TokenScript Viewer
npm i @tokenscript/engine-js
The engine provides a number of interfaces that can be implemented to provide functionality to the engine.
The Card SDK is built as a separate module and bundled with the engine
FAQs
A Typescript implementation of the TokenScript runtime
The npm package @tokenscript/engine-js receives a total of 2 weekly downloads. As such, @tokenscript/engine-js popularity was classified as not popular.
We found that @tokenscript/engine-js demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.