
Research
6 Malicious Packagist Themes Ship Trojanized jQuery and FUNNULL Redirect Payloads
Six malicious Packagist packages posing as OphimCMS themes contain trojanized jQuery that exfiltrates URLs, injects ads, and loads FUNNULL-linked redirects.
@libp2p/bootstrap
Advanced tools
Peer discovery via a list of bootstrap peers
The configured bootstrap peers will be discovered after the configured timeout. This will ensure there are some peers in the peer store for the node to use to discover other peers.
They will be tagged with a tag with the name 'bootstrap' tag, the value 50 and it will expire after two minutes which means the nodes connections may be closed if the maximum number of connections is reached.
Clients that need constant connections to bootstrap nodes (e.g. browsers) can set the TTL to Infinity.
import { createLibp2p } from 'libp2p'
import { bootstrap } from '@libp2p/bootstrap'
const libp2p = await createLibp2p({
peerDiscovery: [
bootstrap({
list: [
// a list of bootstrap peer multiaddrs to connect to on node startup
'/ip4/104.131.131.82/tcp/4001/ipfs/QmaCpDMGvV2BGHeYERUEnRQAwe3N8SzbUtfsmvsqQLuvuJ',
'/dnsaddr/bootstrap.libp2p.io/ipfs/QmNnooDu7bfjPFoTZYxMNLWUQJyrVwtbZg5gBMjTezGAJN',
'/dnsaddr/bootstrap.libp2p.io/ipfs/QmQCU2EcMqAqQPR2i9bChDtGNJchTbq5TbXJJ16u19uLTa'
]
})
]
})
libp2p.addEventListener('peer:discovery', (evt) => {
console.log('found peer: ', evt.detail.toString())
})
$ npm i @libp2p/bootstrap
<script> tagLoading this module through a script tag will make its exports available as Libp2pBootstrap in the global namespace.
<script src="https://unpkg.com/@libp2p/bootstrap/dist/index.min.js"></script>
Licensed under either of
Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.
FAQs
Peer discovery via a list of bootstrap peers
The npm package @libp2p/bootstrap receives a total of 18,493 weekly downloads. As such, @libp2p/bootstrap popularity was classified as popular.
We found that @libp2p/bootstrap demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Six malicious Packagist packages posing as OphimCMS themes contain trojanized jQuery that exfiltrates URLs, injects ads, and loads FUNNULL-linked redirects.

Security News
The GCVE initiative operated by CIRCL has officially opened its publishing ecosystem, letting organizations issue and share vulnerability identifiers without routing through a central authority.

Security News
The project is retiring its odd/even release model in favor of a simpler annual cadence where every major version becomes LTS.