
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@nact/core
Advanced tools

nact ⇒ node.js + actors
your services have never been so µ
Any and all feedback, comments and suggestions are welcome. Please open an issue if you find anything unclear or misleading in the documentation.
This is the repository for the javascript implementation. To view/contribute to the ReasonML code, go to http://github.com/ncthbrt/reason-nact. To contribute to the documentation, https://github.com/ncthbrt/nact.io is the place to make PRs.
Servers today are very different from those even 10 years ago. So why are we still programming like it's the 90s?
Inspired by the approaches taken by Akka and Erlang, Nact is an open source Node.js framework which enables you to take control of your state to:
With out of the box support for event sourcing, and a considered implementation of the actor model, nact can work across a wide variety of domains.
Nact is no silver bullet, but it is evolving to tackle ever more demanding use cases. Perhaps one of them is yours?
To get started, head to https://nact.io
Note: Nact is currently only able to work on Node 8 and above.
You might have noticed that the default branch has been changed to next. That is because Nact is undergoing a signficant rearchitecture.
The aim is to make modularity and extensibility a first class citizen of Nact, while still going to great pains as always to ensure a seamless upgrade path. This work will enable Nact to run in more contexts, such as the browser, deno and of course nact's original platform node. It will also allow for some exciting work in enabling location transparency and being able to more easily design and operate distributed architectures, especially in k8s and cloud contexts.
Of course due to the churn, and because the Nact API surface is expanding, it also seemed prudent to port the codebase over to typescript.
The changes will also require a rewrite of the documentation.
Nact sees daily usage by the project maintainer. The project is extremely stable and has been around for a few years. As the project made the deliberate choice to minimise dependencies, particularly runtime dependencies, there is not a huge need for updates to the project, besides for the occasional introduction of new features. This means that it can be a few months since the last commit. This does not mean the project is dead, but rather that it is working as designed.
We would love to hear how you're using Nact. If you'd like to send feedback (bad or good) please email Natalie Cuthbert at github@ncthbrt.com or join the Discord.
FAQs

The npm package @nact/core receives a total of 6,184 weekly downloads. As such, @nact/core popularity was classified as popular.
We found that @nact/core demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.