
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
@graphprotocol/everest-contracts
Advanced tools
Everest is a DAO that allows any Ethereum account to apply as a member. Whitelisted members can then challenge any member they believe is representing themselves incorrectly, and with a majority vote they can be removed from the list.
Everest is a DAO that allows any Ethereum account to apply as a member. Whitelisted members can then challenge any member they believe is representing themselves incorrectly, and with a majority vote they can be removed from the list.
Everest is used specifically to curate a list of crypto projects. However, it is encouraged that this code is forked, and used to curate any list.
These instructions are specific to just deploying contracts. The root folder has more instructions for deploying the whole dapp.
Run yarn build
The package.json
has a command yarn build
that will run truffle build
, run a script to
extract the abis, and run a script to create flattened contracts.
This project uses Prettier, Solium, and eslint. Node scripts are in package.json
to help.
v5.0.43
.
The command is yarn global add truffle
yarn
at contracts root directoryganache-cli -d -l 9900000 -i 9545
. Note - we use 9,900,000 because that is
what mainnet eth is doing today (Dec 2019)truffle test
CRTL-C
, and then start it up again and run truffle test
See addresses.json
yarn deploy-ropsten
. Mainnet is yarn deploy-mainnet
.addresses.json
FAQs
Everest is a DAO that allows any Ethereum account to apply as a member. Whitelisted members can then challenge any member they believe is representing themselves incorrectly, and with a majority vote they can be removed from the list.
We found that @graphprotocol/everest-contracts demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 35 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.