
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
@fusebit/cli
Advanced tools
The Fusebit CLI is a command-line tool for the management of Fusebit accounts, users, functions and more. For more information about the Fusebit platform, see [https://fusebit.io](https://fusebit.io)
The Fusebit CLI is a command-line tool for the management of Fusebit accounts, users, functions and more. For more information about the Fusebit platform, see https://fusebit.io
The Fusebit CLI is built on node.js, which is a pre-requisite you need to install first. Then, run the following command:
npm install -g @fusebit/cli
To start using the CLI against your deployment, you will need a one-time initialization token, which will be provided during onboarding or when you are given access.
fuse init {initialization-token}
After the command completes, a local profile is created and stored on your machine under ~/.fusebit
. The profile contains private connection information that enables the CLI to communicate with the Fusebit service, and should not be shared.
A profile can also optionally specify a Fusebit boundary and function, which will result in all commands that take those as parameters to default to the values provided in the profile. If you frequently work within the same boundary or on the same function, this is a useful way to save time. Multiple profiles can be created with combinations of boundary and function defaults via the fuse profile
command.
The Fusebit CLI supports the following top-level commands. Each command displays further information when invoked with no parameters:
fuse init
: Initialize the CLI with a one-time token provided by account administratorfuse function
: Manage functions, view function logs, download functions for local development. More details here: [Local Development with the Fusebit CLI]({{ site.baseurl}}{% link authoring-guide/local-development.md %})fuse profile
: Manage profilesfuse token
: Generate a short-lived access token to be used with the HTTP APIfuse user
: (account admins) Retrieve and manage users and their identities and access. More details here: [Managing End-Users within the Fusebit Platform]({{ site.baseurl}}{% link integrator-guide/setting-up-your-team.md %})fuse client
: (account admins) Retrieve and manage clients and their identities and access. More details here: [Setting up your Team]({{ site.baseurl}}{% link integrator-guide/backend-integration.md %}#managing-end-users-within-the-fusebit-platform)fuse issuer
: (account admins) Retrieve and manage trusted issuers associated with the accountfuse version
: Return the version of the Fusebit CLITo update the Fusebit CLI to the latest version, use:
npm install -g @fusebit/cli
To uninstall the Fusebit CLI, use the following command:
npm uninstall -g @fusebit/cli
For security reasons, you may also choose to remove any profiles that were stored locally:
rm -r ~/.fusebit
FAQs
The Fusebit CLI is a command-line tool for the management of Fusebit accounts, users, functions and more. For more information about the Fusebit platform, see [https://fusebit.io](https://fusebit.io)
The npm package @fusebit/cli receives a total of 278 weekly downloads. As such, @fusebit/cli popularity was classified as not popular.
We found that @fusebit/cli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.