
Research
SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflows and Poisons AI Toolchains
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.
@daimo/pay
Advanced tools
Seamless crypto payments. Onboard users from any chain, any coin into your app with one click.
Daimo Pay enables seamless crypto payments for your app.
Onboard users from any chain, any coin into your app with one click and maximize your conversion.
and much more...
You can find the full Daimo Pay documentation here.
Check out https://github.com/daimo-eth/daimo-pay-demo
Coming soon.
Clone the repository and build the SDK in dev mode:
git clone https://github.com/daimo-eth/pay.git
cd pay/packages/connectkit
npm i
npm run dev
The rollup bundler will now watch file changes in the background. Try using one of the examples for testing:
cd examples/nextjs
npm i
npm run dev
Any changes will be reflected on the Pay button in the example app.
Daimo Pay is noncustodial and runs on open-source, audited contracts. See /packages/contract.
Audits:
Contact us if you'd like to integrate Daimo Pay.
See LICENSE for more information.
Daimo Pay SDK uses a fork of ConnectKit, developed by Family. We're grateful to them for making ConnectKit open-source.
FAQs
Seamless crypto payments. Onboard users from any chain, any coin into your app with one click.
The npm package @daimo/pay receives a total of 1,601 weekly downloads. As such, @daimo/pay popularity was classified as popular.
We found that @daimo/pay demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.

Company News
Socket is proud to join the OpenJS Foundation as a Silver Member, deepening our commitment to the long-term health and security of the JavaScript ecosystem.

Security News
npm now links to Socket's security analysis on every package page. Here's what you'll find when you click through.