Research
Security News
Threat Actor Exposes Playbook for Exploiting npm to Build Blockchain-Powered Botnets
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
@digitalbazaar/x25519-key-agreement-key-2019
Advanced tools
An X25519 (Curve25519) DH key implementation to work with the crypto-ld LDKeyPair API
An X25519 (Curve25519) DH (Diffie-Hellman) key implementation to work with the crypto-ld LDKeyPair API.
TBD
For use with crypto-ld
>= 4.0
.
To actually perform encryption with those keys, we recommend you use
the minimal-cipher
library.
This is a low-level level library to generate and serialize X25519 (Curve25519)
key pairs (uses nacl.box
under the hood).
See also (related specs):
Requires Node.js 12+
To install locally (for development):
git clone https://github.com/digitalbazaar/x25519-key-agreement-key-2019.git
cd x25519-key-agreement-key-2019
npm install
Importing:
const {X25519KeyAgreementKey2019} = require('@digitalbazaar/x25519-key-agreement-key-2019');
// Or, if you're testing code in the interactive Node CLI, right in this repo:
const {X25519KeyAgreementKey2019} = require('./');
Generating:
const keyPair = await X25519KeyAgreementKey2019.generate({
controller: 'did:example:1234'
});
Serializing just the public key:
keyPair.export({publicKey: true});
// ->
{
id: 'did:example:1234#z6LSbh9HiAU2zzBdFMdKZGHfg1UjvAYF8C8kYnkfGKuCxYEB',
type: 'X25519KeyAgreementKey2019',
controller: 'did:example:1234',
publicKeyBase58: '1y8BrfAuXTt9yFZ2cmiMRGG5218Raxbfp2ymsFgFATR'
}
Serializing both the private and public key:
// a different key pair than the previous example
await keyPair.export({publicKey: true, privateKey: true})
// ->
{
id: 'did:example:1234#z6LSjeJZaUHMvEKW7tEJXV4PrSm61NzxxHhDXF6zHnVtDu9g',
type: 'X25519KeyAgreementKey2019',
controller: 'did:example:1234',
publicKeyBase58: '8y8Q4AUVpmbm2VrXzqYSXrYcAETrFgX4eGPJoKrMWXNv',
privateKeyBase58: '95tmYuhqSuJqY77FEg78Zy3LFQ1cENxGv2wMvayk7Lqf'
}
Deserializing:
// Loading public key only
const keyPair = await X25519KeyAgreementKey2019.from({
id: 'did:example:1234#z6LSjeJZaUHMvEKW7tEJXV4PrSm61NzxxHhDXF6zHnVtDu9g',
type: 'X25519KeyAgreementKey2019',
controller: 'did:example:1234',
publicKeyBase58: '8y8Q4AUVpmbm2VrXzqYSXrYcAETrFgX4eGPJoKrMWXNv'
});
See the contribute file!
PRs accepted.
If editing the Readme, please conform to the standard-readme specification.
Commercial support for this library is available upon request from Digital Bazaar: support@digitalbazaar.com
New BSD License (3-clause) © Digital Bazaar
4.1.0 - 2021-03-14
fromEdKeyPair()
is now an alias for fromEd25519VerificationKey2018()
to
maintain backwards compatibility. New code should use
fromEd25519VerificationKey2020()
(or whatever the latest Ed25519 suite is).FAQs
An X25519 (Curve25519) DH key implementation to work with the crypto-ld LDKeyPair API
The npm package @digitalbazaar/x25519-key-agreement-key-2019 receives a total of 5,872 weekly downloads. As such, @digitalbazaar/x25519-key-agreement-key-2019 popularity was classified as popular.
We found that @digitalbazaar/x25519-key-agreement-key-2019 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
Security News
NVD’s backlog surpasses 20,000 CVEs as analysis slows and NIST announces new system updates to address ongoing delays.
Security News
Research
A malicious npm package disguised as a WhatsApp client is exploiting authentication flows with a remote kill switch to exfiltrate data and destroy files.