
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
@alchemy/aa-alchemy
Advanced tools
adapters for @alchemy/aa-core for interacting with alchemy services
@alchemy/aa-alchemy
This package contains AlchemyProvider
, an implementation of SmartAccountProvider
class defined in aa-core
. It also contains middleware for accessing the Alchemy Gas Manager (an ERC-4337 Paymaster) and for doing Fee Estimates according to the expectations of the Alchemy Rundler (an ERC-4337 Bundler). You may also find the util methods helpful. This repo is community maintained and we welcome contributions!
If you are already using the @alchemy/aa-core
package, you can simply install this package and start using the AlchemyProvider
. If you are not using @alchemy/aa-core
, you can install it and follow the instructions in the "Getting started" docs to get started.
yarn add @alchemy/aa-alchemy
npm i -s @alchemy/aa-alchemy
pnpm i @alchemy/aa-alchemy
You can create AlchemyProvider
like so:
import {
LightSmartContractAccount,
getDefaultLightAccountFactoryAddress,
} from "@alchemy/aa-accounts";
import { AlchemyProvider } from "@alchemy/aa-alchemy";
import { LocalAccountSigner, type SmartAccountSigner } from "@alchemy/aa-core";
import { sepolia } from "@alchemy/aa-core";
const chain = sepolia;
const PRIVATE_KEY = "0xYourEOAPrivateKey";
const eoaSigner: SmartAccountSigner =
LocalAccountSigner.privateKeyToAccountSigner(`0x${PRIVATE_KEY}`);
export const provider = new AlchemyProvider({
apiKey: "ALCHEMY_API_KEY", // replace with your alchemy api key of the Alchemy app associated with the Gas Manager, get yours at https://dashboard.alchemy.com/
chain,
}).connect(
(rpcClient) =>
new LightSmartContractAccount({
chain,
owner: eoaSigner,
factoryAddress: getDefaultLightAccountFactoryAddress(chain),
rpcClient,
})
);
3.0.0-alpha.13 (2024-02-16)
Note: Version bump only for package root
FAQs
adapters for @alchemy/aa-core for interacting with alchemy services
The npm package @alchemy/aa-alchemy receives a total of 3,045 weekly downloads. As such, @alchemy/aa-alchemy popularity was classified as popular.
We found that @alchemy/aa-alchemy demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.