
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
@near-wallet/e2e-tests
Advanced tools
An end to end test suite for NEAR Wallet flows. Intended to verify and assert that all major flows are functional.
An end to end test suite for NEAR Wallet flows. Intended to verify and assert that all major flows are functional.
BANK_ACCOUNT
: This is the account id the test suite will use to generate temporary sub accounts for testing.BANK_SEED_PHRASE
: The seed phrase for the BANK_ACCOUNT
TEST_ACCOUNT_SEED_PHRASE
: Seed phrase to use for accounts temporarily generated by the test suite.WALLET_NETWORK
: The wallet network (/mainnet|testnet|betanet/) to run the tests against. defaults to testnetNODE_URL
(optional): The rpc node to use for the test suite's connection to NEAR. defaults to https://rpc.testnet.near.orgWALLET_URL
(optional): The wallet URL to use in the test suite. defaults to https://wallet.testnet.near.orgyarn && yarn run e2e
oryarn && yarn run e2e:debug
to run in debug modeFAQs
An end to end test suite for NEAR Wallet flows. Intended to verify and assert that all major flows are functional.
We found that @near-wallet/e2e-tests demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.