
Research
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.
@celo/bls12377js
Advanced tools
This package implements BLS12-377 in TypeScript. It also contains functions for the generation of BLS proofs of possession, as done in [Celo](https://github.com/celo-org/celo-monorepo).
This package implements BLS12-377 in TypeScript. It also contains functions for the generation of BLS proofs of possession, as done in Celo.
bls12377js is licensed under either of the following licenses, at your discretion.
Apache License Version 2.0 (LICENSE-APACHE or http://www.apache.org/licenses/LICENSE-2.0) MIT license (LICENSE-MIT or http://opensource.org/licenses/MIT) Unless you explicitly state otherwise, any contribution submitted for inclusion in bls12377js by you shall be dual licensed as above (as defined in the Apache v2 License), without any additional terms or conditions.
FAQs
This package implements BLS12-377 in TypeScript. It also contains functions for the generation of BLS proofs of possession, as done in [Celo](https://github.com/celo-org/celo-monorepo).
The npm package @celo/bls12377js receives a total of 941 weekly downloads. As such, @celo/bls12377js popularity was classified as not popular.
We found that @celo/bls12377js demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 20 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.