
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@playt/qrpc
Advanced tools
QRPC is a lightweight queue and scheduling library built for serverless - on top of `bullmq` and `elysia`.
QRPC is a lightweight queue and scheduling library built for serverless - on top of bullmq
and elysia
.
It provides a simple way to manage queues and schedules with a focus on scalability and developer experience.
tRPC
Install QRPC using npm:
npm install qrpc
QRPC provides a CLI to start the server. You can configure the server using command-line arguments.
qrpc --port 3000 --token <your-token> --secret <your-secret>
The payloads are stored unencrypted in the database. Ensure that you do not store sensitive information in the payloads and keep the database secure.
All requests to the processing endpoints contain a jwt token as a Bearer token inside the Authorization
header. This token is generated using the secret key provided in the CLI arguments. The token is used to verify the authenticity of the requests and should be kept secure.
The jwt has an expiration time equal to the configured timeout to prevent replay attacks.
The token
provided in the CLI arguments is used to authenticate requests to the API. Ensure that you keep this token secure and do not expose it publicly.
FAQs
QRPC is a lightweight queue and scheduling library built for serverless - on top of `bullmq` and `elysia`.
The npm package @playt/qrpc receives a total of 24 weekly downloads. As such, @playt/qrpc popularity was classified as not popular.
We found that @playt/qrpc demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.