
Research
/Security News
DuckDB npm Account Compromised in Continuing Supply Chain Attack
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
@matterlabs/hardhat-zksync-toolbox
Advanced tools
zkSync Era Hardhat plugin provides a convenient method for bundling and accessing a range of zkSync-related Hardhat plugins.
Ensure you are using the correct version of the plugin with ethers:
For plugin version <1.0.0:
For plugin version ≥1.0.0:
To install hardhat-zksync-toolbox plugin, run:
npm i -D @matterlabs/hardhat-zksync-toolbox
or
yarn add -D @matterlabs/hardhat-zksync-toolbox ethers zksync-ethers
In addition to the hardhat-zksync-toolbox, zkSync's Era website offers a variety of resources including:
Guides to get started: Learn how to start building on zkSync Era.
Hardhat zkSync Era plugins: Overview and guides for all Hardhat zkSync Era plugins.
Hyperscaling: Deep dive into hyperscaling on zkSync Era.
Contributions are always welcome! Feel free to open any issue or send a pull request.
Go to CONTRIBUTING.md to learn about steps and best practices for contributing to zkSync hardhat tooling base repository.
zkSync Era Discord server: for questions and feedback.
Follow zkSync Era on Twitter
FAQs
zkSync bundle of Hardhat plugins
We found that @matterlabs/hardhat-zksync-toolbox demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
Security News
The MCP Steering Committee has launched the official MCP Registry in preview, a central hub for discovering and publishing MCP servers.
Product
Socket’s new Pull Request Stories give security teams clear visibility into dependency risks and outcomes across scanned pull requests.