
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
@chlodalejandro/project-finder
Advanced tools
So, you operate a server or a Raspberry Pi with a few pet projects on it. You have a bunch of projects, scattered around and doing their own thing, but then you suddenly have to migrate all of those projects. You're can't back up the server data, or need to reinstall the system while preserving files. You never had the foresight of using Docker or Ansible to ensure that every single installation of your project is reproducible in a system completely isolated from your existing server. What now?
The Project Finder aims to look for every pet project in a given folder. It crawls through every directory on your drive, skips whatever it knows is not a project, and then tries to find a project in the remaining directories. It then returns a list of projects, with their (detected) name, path, and how they were determined.
Detection happens through detectors. This usually looks for files specific to a given language or package management system, such as npm, Yarn, Composer, etc.
FAQs
pspspsps for pet projects
The npm package @chlodalejandro/project-finder receives a total of 0 weekly downloads. As such, @chlodalejandro/project-finder popularity was classified as not popular.
We found that @chlodalejandro/project-finder demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.