
Research
/Security News
10 npm Typosquatted Packages Deploy Multi-Stage Credential Harvester
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.
[](https://www.npmjs.com/package/@2bad/tvt) [](https://opensource.org/license/MIT) [ CCTV systems.
npm install tvt
import { Device } from 'tvt'
try {
// Create and initialize a new device instance
const device = await Device.create('192.168.1.100', 9008)
// Login to the device
await device.login('admin', 'password')
// Get device information
const info = await device.getInfo()
console.log(`Connected to ${info.deviceName}`)
// Capture a snapshot
await device.saveSnapshot(0, '/path/to/snapshot.jpg')
// Clean up
await device.dispose()
} catch (error) {
console.error('Error:', error)
}
The main interface for interacting with TVT devices.
class Device {
static create(ip: string, port?: number, settings?: Settings): Promise<Device>
login(user: string, pass: string): Promise<boolean>
logout(): Promise<boolean>
getInfo(): Promise<DeviceInfo>
triggerAlarm(value: boolean): Promise<boolean>
saveSnapshot(channel: number, filePath: string): Promise<boolean>
dispose(): Promise<boolean>
// ... and more
}
See API Documentation for detailed method descriptions.
git clone https://github.com/yourusername/tvt.git
cd tvt
npm install
npm run build
npm test
tvt/
โโโ bin/ # Precompiled SDK libraries
โโโ docs/ # Documentation and examples
โโโ proto/ # Protocol definitions and dissectors
โโโ source/ # TypeScript implementation
โโโ lib/ # Core SDK implementation
โโโ helpers/ # Utility functions
โโโ types/ # TypeScript type definitions
await:// Before
const info = device.info
// After
const info = await device.getInfo()
// Before
const device = new Device('192.168.1.100')
// After
const device = await Device.create('192.168.1.100')
// Before
device.info.deviceName
// After
const info = await device.getInfo()
info.deviceName
Contributions are welcome! Please feel free to submit a Pull Request. For major changes, please open an issue first to discuss what you would like to change.
This project is licensed under the MIT License - see the LICENSE file for details.
This project is not officially associated with TVT Digital Technology Co., Ltd. It is an independent implementation based on research and reverse engineering. Use at your own risk.
FAQs
[](https://www.npmjs.com/package/@2bad/tvt) [](https://opensource.org/license/MIT) [
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.

Product
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.

Security News
Open source dashboard CNAPulse tracks CVE Numbering Authoritiesโ publishing activity, highlighting trends and transparency across the CVE ecosystem.