
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
@bitgo/eth-contracts
Advanced tools
A simple library for building Ethereum smart contract interactions. When offline, or away from a web3 wallet, smart contract interaction is quite difficult. This is because it requires special transaction data that defines a function call on a smart contract. This library intends to improve this experience by providing a simple interface for common smart contract function calls. It also aims to be extensible to a wide variety of contracts.
npm i @bitgo/eth-contracts
The basic usage enables users to specify contracts by name and build transaction data from them.
import { Contract } from '@bitgo/eth-contracts';
const cDAI = new Contract('Compound').instance('cDAI');
const { data, amount, address } = cDAI.methods().mint.call({ mintAmount: '1000000000' });
Users can specify an instance of the contract protocol by address instead of name
import { Contract } from '@bitgo/eth-contracts';
const cDAI = new Contract('Compound').address('0x5d3a536e4d6dbd6114cc1ead35777bab948e3643');
const { data, amount, address } = cDAI.methods().mint.call({ mintAmount: '1000000000' });
The decoder can parse call data and output a human-readable explanation of a given contract call.
import { Decoder } from '@bitgo/eth-contracts';
const decoder = new Decoder();
decoder.decode(Buffer.from('a9059cbb00000000000000000000000010d4f942617a231eb1430c88fe43c8c2050437d90000000000000000000000000000000000000000000000000000000000002710', 'hex'));
{ methodId: '0xa9059cbb',
name: 'transfer',
args:
[ { name: '_to',
type: 'address',
value: '0x10d4f942617a231eb1430c88fe43c8c2050437d9' },
{ name: '_value', type: 'uint256', value: 10000 } ],
contractName: 'StandardERC20' }
The output of this library is well formed as an argument to a BitGo SDK sendMany call. This makes it useful for
integration alongside the Bitgo SDK.
import { Contract } from '@bitgo/eth-contracts';
import { BitGo, Coin } from 'bitgo';
async function sendBitGoTx() {
const bitGo = new BitGo({ env: 'test' });
const baseCoin = bitGo.coin('eth');
const bitGoWallet = await baseCoin.wallets().get({ id: '5941ce2db42fcbc70717e5a898fd1595' });
const cDAI = new Contract('Compound').instance('cDAI');
const transaction = await bitGoWallet.sendMany({
recipients: cDAI.methods().mint.call({ mintAmount: '1000000000' }),
walletPassphrase: 'password'
})
}
sendBitGoTx();
listContractTypes() -- get the available contract types.
const types = Contract.listContractTypes();
// response: ['Compound', 'StandardERC20']
listMethods() -- get the available contract methods.
const types = new Contract('StandardERC20').listMethods();
// response: [{ name: 'transfer', inputs: [...], outputs: [...] }, { name: 'approve', ... }]
methods() -- get contract method builder objects
const types = new Contract('StandardERC20').methods();
// response: { transfer: { call: <function to build transfer> }, approve: { call: <function to build approve> } }
getName() -- get contract name
const types = new Contract('StandardERC20').getName();
// response: StandardERC20
address() -- set contract address
const types = new Contract('StandardERC20').address('0x5d3a536e4d6dbd6114cc1ead35777bab948e3643');
// response: Contract with address set
instance() -- set contract instance
const types = new Contract('StandardERC20').instance('DAI');
// response: Contract with DAI address set
This library supports a limited number of smart contract protocols, as it maintains solidity ABIs locally.
This library is quite extensible to new protocols -- if there are other contract types that you would like to use, feel free to submit a PR adding them. To do so, make the following changes:
abis directory, named [ProtocolName].jsonconfig/instances.json
examples directoryFAQs
A library to build Ethereum smart contract function calls.
The npm package @bitgo/eth-contracts receives a total of 20,258 weekly downloads. As such, @bitgo/eth-contracts popularity was classified as popular.
We found that @bitgo/eth-contracts demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.