Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
@devtea2026/temporibus-totam-a-accusantium
Advanced tools
@devtea2026/temporibus-totam-a-accusantium is a small node module that pipes streams together and destroys all of them if one of them closes.
npm install @devtea2026/temporibus-totam-a-accusantium
When using standard source.pipe(dest)
source will not be destroyed if dest emits close or an error.
You are also not able to provide a callback to tell when then pipe has finished.
@devtea2026/temporibus-totam-a-accusantium does these two things for you
Simply pass the streams you want to pipe together to @devtea2026/temporibus-totam-a-accusantium and add an optional callback
var @devtea2026/temporibus-totam-a-accusantium = require('@devtea2026/temporibus-totam-a-accusantium')
var fs = require('fs')
var source = fs.createReadStream('/dev/random')
var dest = fs.createWriteStream('/dev/null')
@devtea2026/temporibus-totam-a-accusantium(source, dest, function(err) {
console.log('pipe finished', err)
})
setTimeout(function() {
dest.destroy() // when dest is closed @devtea2026/temporibus-totam-a-accusantium will destroy source
}, 1000)
You can use @devtea2026/temporibus-totam-a-accusantium to pipe more than two streams together as well
var transform = someTransformStream()
@devtea2026/temporibus-totam-a-accusantium(source, transform, anotherTransform, dest, function(err) {
console.log('pipe finished', err)
})
If source
, transform
, anotherTransform
or dest
closes all of them will be destroyed.
Similarly to stream.pipe()
, @devtea2026/temporibus-totam-a-accusantium()
returns the last stream passed in, so you can do:
return @devtea2026/temporibus-totam-a-accusantium(s1, s2) // returns s2
Note that @devtea2026/temporibus-totam-a-accusantium
attaches error handlers to the streams to do internal error handling, so if s2
emits an
error in the above scenario, it will not trigger a proccess.on('uncaughtException')
if you do not listen for it.
If you want to return a stream that combines both s1 and s2 to a single stream use @devtea2026/temporibus-totam-a-accusantiumify instead.
MIT
@devtea2026/temporibus-totam-a-accusantium
is part of the mississippi stream utility collection which includes more useful stream modules similar to this one.
Available as part of the Tidelift Subscription.
The maintainers of @devtea2026/temporibus-totam-a-accusantium and thousands of other packages are working with Tidelift to deliver commercial support and maintenance for the open source dependencies you use to build your applications. Save time, reduce risk, and improve code health, while paying the maintainers of the exact dependencies you use. Learn more.
FAQs
Unknown package
The npm package @devtea2026/temporibus-totam-a-accusantium receives a total of 0 weekly downloads. As such, @devtea2026/temporibus-totam-a-accusantium popularity was classified as not popular.
We found that @devtea2026/temporibus-totam-a-accusantium demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.