
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
@near-wallet-selector/core
Advanced tools
This is the core package for NEAR Wallet Selector.
The easiest way to use this package is to install it from the NPM registry, this package requires near-api-js
v1.0.0 or above:
# Using Yarn
pnpm add -w near-api-js
# Using NPM.
npm install near-api-js
# Using Yarn
pnpm add -w @near-wallet-selector/core
# Using NPM.
npm install @near-wallet-selector/core
Then use it in your dApp:
import { setupWalletSelector } from "@near-wallet-selector/core";
import { setupMyNearWallet } from "@near-wallet-selector/my-near-wallet";
// The entire set of options can be found in the section below.
const selector = await setupWalletSelector({
network: "testnet",
modules: [setupMyNearWallet()],
});
// Example with createAccessKeyFor for limited access keys
const selectorWithLimitedAccess = await setupWalletSelector({
network: "testnet",
modules: [setupMyNearWallet()],
createAccessKeyFor: {
contractId: "guest-book.testnet",
methodNames: ["addMessage", "getMessages"]
},
});
network
(NetworkId | Network
): Network ID or object matching that of your dApp configuration . Network ID can be either mainnet
or testnet
.
networkId
(string
): Custom network ID (e.g. localnet
).nodeUrl
(string
): Custom URL for RPC requests.helperUrl
(string
): Custom URL for creating accounts.explorerUrl
(string
): Custom URL for the NEAR explorer.indexerUrl
(string
): Custom URL for the Indexer service.debug
(boolean?
): Enable internal logging for debugging purposes. Defaults to false
.optimizeWalletOrder
(boolean?
): Enable automatic wallet order. Reorders last signed in wallet on top, then installed wallets over not installed and deprecated wallets.randomizeWalletOrder
(boolean?
): Randomize wallets order in the More
section of the UI.allowMultipleSelectors
(boolean?
): Optionally allow creating new instances of wallet selector.languageCode
(string?
): Optionally set specific ISO 639-1 two-letter language code, disables language detection based on the browser's settings.relayerUrl
(string?
): Optionally set the URL that meta-transaction enabled wallet modules can use to submit DelegateActions to a relayercreateAccessKeyFor
(object?
): The contract ID and method names to create a function call access key for. This allows wallets to create limited access keys for specific contract methods.
contractId
(string
): The contract ID to create the access key for.methodNames
(Array<string>
): Array of method names that the access key will be limited to.storage
(StorageService?
): Async storage implementation. Useful when localStorage
is unavailable. Defaults to localStorage
.modules
(Array<WalletModuleFactory>
): List of wallets to support in your dApp.You can find the entire API reference for Wallet Selector here.
This repository is distributed under the terms of both the MIT license and the Apache License (Version 2.0).
FAQs
This is the core package for NEAR Wallet Selector.
We found that @near-wallet-selector/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.