
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
@originjs/crypto-js-wasm
Advanced tools
An alternative to crypto-js implemented with WebAssembly and ESM
crypto-js-wasm
is a javascript library of crypto standards. Inspired by crypto-js, but now powered by WebAssembly.
browser
and nodejs
RSA is supported now!
npm install @originjs/crypto-js-wasm
or
pnpm install @originjs/crypto-js-wasm
or
yarn add @originjs/crypto-js-wasm
Note that the async function loadWasm()
should be called once (and once only!) for each algorithm that will be used, unless loadAllWasm()
is called at the very beginning.
import CryptoJSW from 'crypto-js-wasm';
// (Optional) load all wasm files
await CryptoJSW.loadAllWasm();
// Async/Await syntax
await CryptoJSW.MD5.loadWasm();
const rstMD5 = CryptoJSW.MD5('message').toString();
console.log(rstMD5);
// Promise syntax
CryptoJSW.SHA256.loadWasm().then(() => {
const rstSHA256 = CryptoJSW.SHA256('message').toString();
console.log(rstSHA256);
})
Please note that HMAC
does not have a loadWasm
, as a hasher must be specified if you want to use HMAC
(i.e. HmacSHA1
).
And the loadWasm
in pbkdf2
only calls SHA1.loadWasm
as SHA1
is the default hasher of pbkdf2
. If you specified another hasher, the corresponding loadWasm
of the hasher should be called repectly. Same case in evpkdf
/MD5
as MD5
is the default hasher of evpkdf
.
Usage of RSA
Please refer to this document.
Available standards
The benchmark below is run on a desktop PC (i5-4590, 16 GB RAM, Windows 10 Version 21H2 (OSBuild 19044, 1466)).
Chrome 102.0.5005.63:
Firefox 101.0:
Nodejs v16.6.4:
# install dependencies
pnpm install
# build for production
pnpm run build
# run all tests
pnpm run test
# run all tests with coverage
pnpm run coverage
This is because the WebAssembly binary needs to be load by WebAssembly.instantiate
, and it is async.
The async WebAssembly.instantiate
is recommended instead of its sync variant WebAssembly.instance
, and in many cases the WebAssembly.instance
can not load WebAssembly binary whose size is not small enough.
This is because crypto-js-wasm
may be used in browser
or nodejs
. This is relative elegant implementation comparing with wasm loader
in browser
(powered by webpack, vite or something else) or fs
in nodejs
.
Distributed under the Mulan Permissive Software License
FAQs
An alternative to crypto-js implemented with WebAssembly and ESM
The npm package @originjs/crypto-js-wasm receives a total of 53 weekly downloads. As such, @originjs/crypto-js-wasm popularity was classified as not popular.
We found that @originjs/crypto-js-wasm demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.