
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
@celo/bls12377js
Advanced tools
This package implements BLS12-377 in TypeScript. It also contains functions for the generation of BLS proofs of possession, as done in [Celo](https://github.com/celo-org/celo-monorepo).
This package implements BLS12-377 in TypeScript. It also contains functions for the generation of BLS proofs of possession, as done in Celo.
bls12377js is licensed under either of the following licenses, at your discretion.
Apache License Version 2.0 (LICENSE-APACHE or http://www.apache.org/licenses/LICENSE-2.0) MIT license (LICENSE-MIT or http://opensource.org/licenses/MIT) Unless you explicitly state otherwise, any contribution submitted for inclusion in bls12377js by you shall be dual licensed as above (as defined in the Apache v2 License), without any additional terms or conditions.
FAQs
This package implements BLS12-377 in TypeScript. It also contains functions for the generation of BLS proofs of possession, as done in [Celo](https://github.com/celo-org/celo-monorepo).
The npm package @celo/bls12377js receives a total of 459 weekly downloads. As such, @celo/bls12377js popularity was classified as not popular.
We found that @celo/bls12377js demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 20 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.