
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
@coasys/ad4m-connect
Advanced tools
Lib for handling everything needed to setup a connection to a local or remote ad4m-executor
A powerful library that simplifies connecting applications to AD4M executors by handling:
AD4M uses a capability-based security model to protect user data and control access to agent functionality. Every application that wants to interact with an AD4M executor needs to request specific capabilities, which are then granted (or denied) by the user.
Capabilities in AD4M are like permission tokens that:
A capability token might grant permissions like:
npm install -s @coasys/ad4m-connect
When an application wants to connect to an AD4M executor, it goes through a secure authentication handshake:
Initial Connection Screen:
Executor Found:
Authorization Request:
Verification Code:
import Ad4mConnectUI from "@coasys/ad4m-connect";
const ui = Ad4mConnect({
// Required parameters
appName: "My AD4M App",
appDesc: "A description of what your app does",
appDomain: "myapp.com",
capabilities: [{
with: { domain: "*", pointers: ["*"] },
can: ["*"]
}],
// Optional parameters
appIconPath: "https://myapp.com/icon.png",
port: 12345, // Custom port
token: "existing-token", // Existing JWT token
url: "custom-executor-url" // Custom executor URL
});
// Listen for authentication state changes
ui.addEventListener("authstatechange", (e) => {
switch(e.detail) {
case "authenticated":
console.log("Successfully authenticated");
break;
case "unauthenticated":
console.log("Not authenticated");
break;
case "locked":
console.log("Agent is locked");
break;
}
});
// Connect and get AD4M client
ui.connect().then((client) => {
// Client is now ready to use
console.log("Connected with capabilities");
});
const { ad4mConnect } = require("@coasys/ad4m-connect/electron");
ad4mConnect({
// Provide the name of your app to be displayed in the dialog
appName: "Perspect3ve",
// Provide an icon to be displayed in the dialog as well
appIconPath: path.join(__dirname, "graphics", "Logo.png"),
// Name the capabilities your app needs
// (this is an example with all capabilities)
capabilities: [{ with: { domain: "*", pointers: ["*"] }, can: ["*"] }],
// Provide a directory in which the capability token and the executor
// URL will be stored such that future calls won't even open a dialog
// but try the token against that URL and resolve immediately
// if it works.
dataPath: path.join(homedir(), ".perspect3ve"),
})
.then(({ client, capabilityToken, executorUrl }) => {
// Retrieved `capabilityToken` and selected `executorUrl` are returned
// but all that is really needed is `client` which is a fully setup
// (including capability token) and working Ad4mClient.
//
// Both, the URL and the token have already been stored on disk
// in the directory provided as `dataPath`.
//
// Consequetive calls
createWindow(client);
})
.catch(() => {
console.log("User closed AD4M connection wizard. Exiting...");
app.exit(0);
process.exit(0);
});
When requesting capabilities, specify:
{
with: {
domain: string | "*", // Which perspective/domain
pointers: string[] | "*" // Which parts of the domain
},
can: string[] | "*" // Which operations are allowed
}
Examples:
// Full access (development only)
{ with: { domain: "*", pointers: ["*"] }, can: ["*"] }
// Read-only access to a perspective
{ with: { domain: "perspective-uuid", pointers: ["*"] }, can: ["read"] }
// Specific operations on a domain
{ with: { domain: "friends", pointers: ["*"] }, can: ["read", "add", "remove"] }
The library emits various events to help track connection state:
authstatechange
:
authenticated
: Successfully connected with capabilitiesunauthenticated
: No valid authenticationlocked
: Agent is lockedconnectionstatechange
:
connecting
: Attempting to connectconnected
: Successfully connectednot_connected
: No connectiondisconnected
: Lost connectionerror
: Connection errorconfigstatechange
: Configuration changes for token
, url
, or port
Add to android/app/src/main/AndroidManifest.xml
:
<?xml version="1.0" encoding="utf-8"?>
<manifest
xmlns:android="http://schemas.android.com/apk/res/android"
+ xmlns:tools="http://schemas.android.com/tools"
package="com.example">
<application
+ android:hardwareAccelerated="true"
>
</application>
+ <uses-permission android:name="android.permission.CAMERA" />
+ <uses-sdk tools:overrideLibrary="com.google.zxing.client.android" />
</manifest>
Add to Info.plist
:
<dict>
+ <key>NSCameraUsageDescription</key>
+ <string>To be able to scan barcodes</string>
</dict>
After changes, run:
npx cap sync
npx cap build
Request Minimal Capabilities
Handle Authentication States
Secure Storage
User Experience
For more details about AD4M authentication and capabilities:
FAQs
Lib for handling everything needed to setup a connection to a local or remote ad4m-executor
The npm package @coasys/ad4m-connect receives a total of 309 weekly downloads. As such, @coasys/ad4m-connect popularity was classified as not popular.
We found that @coasys/ad4m-connect demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.