
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@extendohub/cli
Advanced tools
eh
, the ExtendoHub CLI supports extension development making it easy to develop and test extensions locally and interact with ExtendoHub services (e.g., logging).
eh
can be installed using npm as a global (or local) command using
npm i -g @extendohub/cli
User is developing an extension and wants to debug/iterate. Use the CLI to run their code.
Compute
or Service
(e.g., JavaScript)? We are going to trigger the "runtime" which is pretty low level. Perhaps we need a local Compute
User is doing web based development and want to try their code (e.g., Click the Run button) and see the output. This is largely the same as debug/CLI scenario but no debug.
For example, run the midnight
worker in Hubble
Final validation that the deployed thing works
Extension is determined by normal extension point logic
Code comes from installed extension
FAQs
ExtendoHub CLI
The npm package @extendohub/cli receives a total of 19 weekly downloads. As such, @extendohub/cli popularity was classified as not popular.
We found that @extendohub/cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.