
Research
NPM targeted by malware campaign mimicking familiar library names
Socket uncovered npm malware campaign mimicking popular Node.js libraries and packages from other ecosystems; packages steal data and execute remote code.
@polkadot/api-cli
Advanced tools
A simple cli interface to the @polkadot/api.
Commands are of the form,
yarn run:api [options] <type> <...params>
Where type is the type of query to be made, this takes the form of <type>.<section>.<method>
where type
is one of consts
, derive
, query
, rpc
tx
(mapping to the API) and the section
and method
are available calls.
For instance to make a query to retrieve Alice's balances, you can do
yarn run:api query.system.account 5GrwvaEF5zXb26Fz9rcQpDWS57CtERHpNehXCPcNoHGKutQY
To do the same, running as a subscription and streaming results
yarn run:api query.system.account 5GrwvaEF5zXb26Fz9rcQpDWS57CtERHpNehXCPcNoHGKutQY --sub
To make a transfer from Alice to Bob, the following can be used -
yarn run:api tx.balances.transfer 5FHneW46xGXgs5mUiveU4sbTyGBzmstUspZC92UhjJM694ty 12345 --seed "//Alice"
You can pass complex parameters as JSON which will be automatically parsed into the correct data structure
yarn run:api --sudo tx.validatorManager.registerValidators '["5GrwvaEF5zXb26Fz9rcQpDWS57CtERHpNehXCPcNoHGKutQY","5FHneW46xGXgs5mUiveU4sbTyGBzmstUspZC92UhjJM694ty"]'
It is often desirable to include large binary blobs as transaction parameters. These blobs are often already present in the local filesystem. Therefore, the CLI has special syntax to make life easier: any transaction parameter whose initial character is @
is treated as a path to a binary file; its contents are automatically converted into appropriate hex form before sending the tx.
The sudo
example demonstrates this.
Some transactions require superuser access. For example, to change the runtime code, you can do
yarn run:api --sudo --seed "//Alice" tx.system.setCode @test.wasm
In all cases when sudoing, the seed provided should be that of the superuser. For most development nets, that is "//Alice"
.
$ yarn global add @polkadot/api-cli
$ polkadot-js-api ...
The --ws
param can be used to connect to other Websocket endpoints, when submitting transactions, you can use the --seed <seed>
to specify an account seed. To read documentation on a call, use the --info
command.
To specify types for a specific chain, you can use the --types <types.json>
param, injecting the specified types into the API on construction.
To specify RPC types for a specific chain, you can use the --rpc <rpc.json>
param, injecting the specified RPC types into the API on construction.
For a complete list of available commands, you can use --help
FAQs
A commandline API interface for interacting with a chain
The npm package @polkadot/api-cli receives a total of 693 weekly downloads. As such, @polkadot/api-cli popularity was classified as not popular.
We found that @polkadot/api-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovered npm malware campaign mimicking popular Node.js libraries and packages from other ecosystems; packages steal data and execute remote code.
Research
Socket's research uncovers three dangerous Go modules that contain obfuscated disk-wiping malware, threatening complete data loss.
Research
Socket uncovers malicious packages on PyPI using Gmail's SMTP protocol for command and control (C2) to exfiltrate data and execute commands.