
Research
TeamPCP Compromises Telnyx Python SDK to Deliver Credential-Stealing Malware
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.
@solana/nominal-types
Advanced tools
This package contains type utilities for creating nominal types in TypeScript.
Use the Brand utility to produce a new type that satisfies the original type, but not the other way around. That is to say, the branded type is acceptable wherever the original type is specified, but wherever the branded type is specified, the original type will be insufficient.
You can use this to create specialized instances of strings, numbers, objects, and more which you would like to assert are special in some way (eg. numbers that are non-negative, strings which represent the names of foods, objects that have passed validation).
const unverifiedName = 'Alice';
const verifiedName = unverifiedName as Brand<'Alice', 'VerifiedName'>;
'Alice' satisfies Brand<string, 'VerifiedName'>; // ERROR
'Alice' satisfies Brand<'Alice', 'VerifiedName'>; // ERROR
unverifiedName satisfies Brand<string, 'VerifiedName'>; // ERROR
verifiedName satisfies Brand<'Bob', 'VerifiedName'>; // ERROR
verifiedName satisfies Brand<'Alice', 'VerifiedName'>; // OK
verifiedName satisfies Brand<string, 'VerifiedName'>; // OK
Use the CompressedData utility to produce a new type that satisfies the original type, but adds extra type information that marks the type as containing compressed data.
const untaggedData = new Uint8Array([/ ... *\/]);
const compressedData = untaggedData as CompressedData<typeof untaggedData, 'zstd'>;
compressedData satisfies CompressedData<Uint8Array, 'zstd'>; // OK
untaggedData satisfies CompressedData<Uint8Array, 'zstd'>; // ERROR
const untaggedString = 'dv1ZAGvdsz5hHLwWXsVnM94hWf1pjbKVau1QVkaMJ92';
const encodedString = untaggedString as EncodedString<typeof untaggedString, 'base58'>;
encodedString satisfies EncodedString<'dv1ZAGvdsz5hHLwWXsVnM94hWf1pjbKVau1QVkaMJ92', 'base58'>; // OK
encodedString satisfies EncodedString<string, 'base58'>; // OK
encodedString satisfies EncodedString<string, 'base64'>; // ERROR
untaggedString satisfies EncodedString<string, 'base58'>; // ERROR
const encodedCompressedString = 'abc' as Brand<
EncodedString<CompressedData<'abc', 'zstd'>, 'base64'>,
'Base64ZstdCompressedData'
>;
encodedCompressedString satisfies Brand<'abc', 'Base64ZstdCompressedData'>; // OK
encodedCompressedString satisfies Brand<string, 'Base64ZstdCompressedData'>; // OK
encodedCompressedString satisfies CompressedData<'abc', 'zstd'>; // OK
encodedCompressedString satisfies CompressedData<string, 'zstd'>; // OK
encodedCompressedString satisfies EncodedString<'abc', 'base64'>; // OK
encodedCompressedString satisfies EncodedString<string, 'base64'>; // OK
encodedCompressedString satisfies EncodedString<string, 'base58'>; // ERROR
type SweeteningSubstance = 'aspartame' | 'cane-sugar' | 'stevia';
type Sweetener<T extends SweeteningSubstance> = NominalType<'sweetener', T>;
// This function accepts sweetened foods, except those with aspartame.
declare function eat(food: string & Sweetener<Exclude<SweeteningSubstance, 'aspartame'>>): void;
const artificiallySweetenedDessert = 'ice-cream' as string & Sweetener<'aspartame'>;
eat(artificiallySweetenedDessert); // ERROR
FAQs
Type utilties for creating nominal/branded types in TypeScript
The npm package @solana/nominal-types receives a total of 676,901 weekly downloads. As such, @solana/nominal-types popularity was classified as popular.
We found that @solana/nominal-types demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.

Security News
/Research
Widespread GitHub phishing campaign uses fake Visual Studio Code security alerts in Discussions to trick developers into visiting malicious website.