
Research
/Security News
DuckDB npm Account Compromised in Continuing Supply Chain Attack
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
A MITM proxy application with incoming IPv4/IPv6 and random outgoing IPv6
A MITM proxy application with incoming IPv4/IPv6 and random outgoing IPv6
4proxy6 is a MITM proxy that redirects HTTP/HTTPS traffic to one random IPv6 address attached in your network interfaces.
Each incoming HTTP request must have the uuid
header. All HTTP requests made
with the same uuid
header will use the same IPv6 exit address, within a
certain amount of time (default: 30 minutes).
You may use this package with node 4proxy6.js
or using one of the binaries
provided in the releases section.
If you use npm: npm install -g 4proxy6
. You will be able to use it system-wide.
Usage: 4proxy6 [options]
Options:
-a, --address <address> IPv6 address of the outgoing interface
-b, --prefix_bits <number> number of bits for IPv6 address prefix (default: 48)
-c, --credentials <user:password> user and password for proxy authentication
-p, --port <address> port for listening (default: 3322)
-t, --ttl <TTL> TTL for cache (default: 1800)
-h, --help output usage information
address
: base IPv6 address of the interface the proxy will use as exit.prefix_bits
: number of bits in the IPv6 address that must not be changed.
All other bits will be randomly generated. Example: --address 2001:1234::
and --prefix_bits 16
will generate random exit addresses between
2001:0000:0000:0000:0000:0000:0000:0000
and
2001:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF
.credentials
: user and password for proxy authentication, formated like
user:password
. If you don't want authentication, just don't add this flag.port
: TCP port for the proxy.ttl
: amount of seconds a uuid
will hold the same IPv6 address.FAQs
A MITM proxy application with incoming IPv4/IPv6 and random outgoing IPv6
We found that 4proxy6 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
Security News
The MCP Steering Committee has launched the official MCP Registry in preview, a central hub for discovering and publishing MCP servers.
Product
Socket’s new Pull Request Stories give security teams clear visibility into dependency risks and outcomes across scanned pull requests.