
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
@ag_dubs/js-hello-world
Advanced tools
an example rust -> wasm project
🌌 0.2.0
This release focuses on filling out all commands and improving stderr/out handling for improved user experience!
pack
and publish
- [jamiebuilds], [pull/67]
You can now run wasm-pack pack
to generate a tarball of your generated package,
as well as run wasm-pack publish
to publish your package to the npm registry.
Both commands require that you have npm installed, and the publish
command requires
that you be logged in to the npm client. We're working on wrapping the npm login
command so that you can also login directly from wasm-pack
, see [pull/100] for more
details.
package.json
is pretty printed now - [yoshuawuyts], [pull/70]
Previously, package.json
was not very human readable. Now it is pretty printed!
collaborators
- [yoshuawuyts], [pull/70]
wasm-pack
now will fill out the collaborators
field in your package.json
for
you based on your Cargo.toml
authors
data. For more discussion on how we decided
on this v.s. other types of author
fields in package.json
, see [issues/2].
Release binaries built with CI - [ashleygwilliams], [pull/103]
Optional package.json
fields warn instead of failing - [mgattozzi], [pull/65]
Program doesn't swallow stout and sterr - [mgattozzi], [pull/90]
Thanks so much to [mgattozzi], [data-pup], [sendilkumarn], [Andy-Bell], [steveklabnik], [jasondavies], and [edsrzf] for all the awesome refactoring, documentation, typo-fixing, and testing work. We appreciate it so much!
FAQs
an example rust->wasm crate
The npm package @ag_dubs/js-hello-world receives a total of 0 weekly downloads. As such, @ag_dubs/js-hello-world popularity was classified as not popular.
We found that @ag_dubs/js-hello-world demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.