Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@peacechen/react-native-otp-autocomplete
Advanced tools
React native sms verification without additional permissions.
This is a fork of https://github.com/jmlavoier/react-native-otp-autocomplete and published as a separate package on [npmjs.com](https://www.npmjs.com/package/@peacechen/react-native-otp-autocomplete to unlock the peer dependencies. That package was forked from react-native-otp-verify which was deprecated.
It uses Automatic SMS Verification with the SMS Retriever API. With the SMS Retriever API, you can perform SMS-based user verification in your Android app automatically, without requiring the user to manually type verification codes, and without requiring any extra app permissions.
In order to detect the message, SMS message must include a hash that identifies your app. This hash can be obtained by using the getHash() method below.
Please read the official documentation for the message structure at this Google developer guide
$ npm install @peacechen/react-native-otp-autocomplete --save
or
$ yarn @peacechen/react-native-otp-autocomplete
$ react-native link @peacechen/react-native-otp-autocomplete
android/app/src/main/java/[...]/MainActivity.java
import com.jmlavoier.OtpAutocomplete.RNOtpAutocompletePackage;
to the imports at the top of the filenew RNOtpAutocompletePackage()
to the list returned by the getPackages()
methodandroid/settings.gradle
:
include ':@peacechen/react-native-otp-autocomplete'
project(':@peacechen/react-native-otp-autocomplete').projectDir = new File(rootProject.projectDir, '../node_modules/@peacechen/react-native-otp-autocomplete/android')
android/app/build.gradle
:
compile project(':@peacechen/react-native-otp-autocomplete')
import OtpAutocomplete from '@peacechen/react-native-otp-autocomplete';
const getHash = () =>
OtpAutocomplete.getHash()
.then(console.log)
.catch(console.log);
const startListeningForOtp = () =>
OtpAutocomplete.getOtp()
.then(p => OtpAutocomplete.addListener(otpHandler))
.catch(p => console.log(p));
const otpHandler = (message: string) => {
const otp = /(\d{4})/g.exec(message)[1];
this.setState({ otp });
OtpAutocomplete.removeListener();
Keyboard.dismiss();
}
useEffet(() => {
startListeningForOtp();
return () => OtpAutocomplete.removeListener();
}, [startListeningForOtp]);
getOtp():Promise<boolean>
Start listening for OTP/SMS. Return true if listener starts else throws error.
getHash():Promise<string[]>
Gets the hash code for the application which should be added at the end of message. This is just a one time process.
addListener(handler:(message:string)=>any):Promise<boolean>
Adds a javascript listener to the handler passed which is called when message is received.
removeListener():void
Removes the listener.
FAQs
React native sms verification without additional permissions.
The npm package @peacechen/react-native-otp-autocomplete receives a total of 69 weekly downloads. As such, @peacechen/react-native-otp-autocomplete popularity was classified as not popular.
We found that @peacechen/react-native-otp-autocomplete demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.