
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
@aztec/blob-sink
Advanced tools
A HTTP api that losely emulates the https://ethereum.github.io/beacon-APIs/?urls.primaryName=dev#/Beacon/getBlobSidecars API. We do not support all of the possible values of block_id, namely `genesis`, `head`, `finalized`. As we are not using any of these
A HTTP api that losely emulates the https://ethereum.github.io/beacon-APIs/?urls.primaryName=dev#/Beacon/getBlobSidecars API.
We do not support all of the possible values of block_id, namely genesis
, head
, finalized
. As we are not using any of these values in our
blobs integration.
This service will run alongside end to end tests to capture the blob transactions that are sent alongside a propose
transaction.
Once we make the transition to blob transactions, we will need to be able to query for blobs. One way to do this is to run an entire L1 execution layer and consensus layer pair alongside all of our e2e tests and inside the sandbox. But this is a bit much, so instead the blob sink can be used to store and request blobs, without needing to run an entire consensus layer pair client.
Blobs are only held in the L1 consensus layer for a period of ~3 weeks, the blob sink can be used to store blobs for longer.
The blob sink is a simple HTTP server that can be run alongside the e2e tests. It will store the blobs in a local file system and provide an API to query for them.
If no blob sink url or consensus host url is provided: A local version of the blob sink will be used. This stores blobs in a local file system.
Blob sink url is provided: If requesting from the blob sink, we send the blockHash
Consensus host url is provided: If requesting from the beacon node, we send the slot number
FAQs
A HTTP api that losely emulates the https://ethereum.github.io/beacon-APIs/?urls.primaryName=dev#/Beacon/getBlobSidecars API. We do not support all of the possible values of block_id, namely `genesis`, `head`, `finalized`. As we are not using any of these
The npm package @aztec/blob-sink receives a total of 3,395 weekly downloads. As such, @aztec/blob-sink popularity was classified as popular.
We found that @aztec/blob-sink demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.