
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@nodeward/zerocrash
Advanced tools
// Token acquired from the dashboard projects page
const TOKEN = '0ABCDEF12345678901234567890123456789012345678901234567890ABCDEF0';
// Ability to turn on/off any feature that we provide
const options = { alarm: true, events: true, benchmarks: true, crashReporting: true };
// Installing and Initializing the module
const ZeroCrash = require('@nodeward/zerocrash').install(TOKEN, options);
// Before including any route
app.use(ZeroCrash.requestHandler());
// Normal Express routes...
app.get('/', (req, res) => res.json({ message: 'hello world' });
// After including all routes
app.use(ZeroCrash.errorHandler());
This is a Node.js module available through the npm registry.
Before installing, download and install Node.js.
Installation is done using the
npm install
command:
$ npm install @nodeward/zerocrash --save
## !!Replace <token> with the token from the dashboard
## Endpoints Request
curl -X POST \
-d '{"endpoint": "/users/:id", "method": "GET", "startAt": "1544268184321", "end": "1544268181234", "ip": "181.215.95.235", "resStatusCode": "200", "resStatusMessage": "Success"}' \
-H 'Token: <token>' \
-H 'Content-Type: application/json' \
'http://207.154.240.216:5555/library/metrics'
## Exceptions Request
curl -X POST \
-d '{"errMsg":"TypeError", "errName":"cannot read property 'length' of undefined", "filename": "app.js", "colno":"13", "lineno":"80", "pre_context":"let x = [1,2,3]", "context_line":"console.log(y.length)", "post_context":"console.log(`DONE ${x}`)", "function":"getLength"}' \
-H 'Token: <token>' \
-H 'Content-Type: application/json' \
'http://207.154.240.216:5555/library/exceptions'
If you discover a security vulnerability in ZeroCrash, please see Security Policies and Procedures.
The original authors of ZeroCrash are Pierre Raii and Surge
FAQs
---
The npm package @nodeward/zerocrash receives a total of 0 weekly downloads. As such, @nodeward/zerocrash popularity was classified as not popular.
We found that @nodeward/zerocrash demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.