
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
@huma-shan/payment-detection
Advanced tools
@huma-shan/payment-detection is a typescript library part of the Request Network protocol.
It contains the implementation of request-related events interpretations, typically onchain payments of requests.
The interpretation of events is specified by the payment extension added to the request. Cf. advanced-logic specifications.
If a payment network has been given to the request, the payment detection can be done.
Based on information found in the payment network state, and included manual payment declarations, the library will perform queries and feed the property balance of the request with:
balance: the detected amount paid on the request, in request currencyevents: all the payments, payment declarations, refunds, and other balance-related events with the amount, timestamp etc...This library relies on two concepts:
InfoRetrievers, implementing the getTransferEvents() method (cf. IPaymentRetriever)getBalance(), which calls retrievers and interpret events according to the payment network (cf. Abstract PaymentDetectorBase). getBalance() returns the balance as well as events: payments, refunds, and possibly other events (declarations, escrow events...)A good part of the logic is implemented in the abstract class PaymentDetectorBase:
export abstract class PaymentDetectorBase<
TExtension extends ExtensionTypes.IExtension,
TPaymentEventParameters,
> implements PaymentTypes.IPaymentNetwork<TPaymentEventParameters>
{
public async getBalance(
request: RequestLogicTypes.IRequest,
): Promise<PaymentTypes.IBalanceWithEvents<TPaymentEventParameters>> {
// ...
// getEvents() should be implemented by children payment detectors, and use appropriate retrievers
// For example: RPC or The Graph based retriever
const rawEvents = await this.getEvents(request);
// ...
// computeBalance() sums up all payment events and deduces all refunds.
const balance = this.computeBalance(events).toString();
return {
balance,
events,
};
}
}
For TheGraph-based information retrieval, a client can be retrieved using getTheGraphClient() in ./src/thegraph/index.ts. It provides a strongly typed interface, generated based on the queries in /src/thegraph/queries.
The automated type generation is configured within files ./codegen.yml (for EVM chains) and ./codegen-near.yml (for Near) and output in ./src/thegraph/generated. It depends on the deployed subgraphes schema and on the queries.
The code generation is included in the pre-build script and can be run manually:
yarn codegen
The ETH InfoRetriever tests require explorer API keys. Before running the
payment-detection tests, define DISABLE_API_TESTS or define all required
explorer API keys.
export DISABLE_API_TESTS=1
# OR
export EXPLORER_API_KEY_MAINNET=
export EXPLORER_API_KEY_RINKEBY=
export EXPLORER_API_KEY_FUSE=
export EXPLORER_API_KEY_MATIC=
export EXPLORER_API_KEY_FANTOM=
yarn run test
FAQs
Payment detection using ethers.
The npm package @huma-shan/payment-detection receives a total of 4 weekly downloads. As such, @huma-shan/payment-detection popularity was classified as not popular.
We found that @huma-shan/payment-detection demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.