Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@harmony-js/account
Advanced tools
import { Wallet } from '@harmony-js/account';
const wallet = new Wallet();
const mnes = wallet.generateMnemonic();
// add mnemonic and use index=0
const accountA = wallet.addByMnemonic(mnes,0);
// this account instance will be the wallet's signer by default
console.log(wallet.signer.address === accountA.address)
// true
wallet.encryptAccount(accountA.address,'easy password')
.then((encrypted)=>{
console.log(encrypted.privateKey);
// private key now is keyStoreV3 format string
wallet.decryptAccount(accountA.address,'easy password')
.then((decrypted)=>{
console.log(decrypted.privateKey);
// now private key is recovered
})
});
wallet.accounts
// it will display accounts addresses live in wallet
wallet.getAccount(accountA.address);
// it will get account instance by using address as reference
wallet.removeAccount(accountA.address);
// it will remove account instance from wallet
wallet.createAccount();
// it will create a new acount instance
wallet.addByPrivateKey(key);
// you can add private key directly as well
FAQs
account and wallet for harmony
The npm package @harmony-js/account receives a total of 384 weekly downloads. As such, @harmony-js/account popularity was classified as not popular.
We found that @harmony-js/account demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.