Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
@stellar/halting-analysis
Advanced tools
Analyze a transitive quorum to find halting weaknesses. Runs through all the nodes and checks for any combination of N failures which can cause your node to halt. This is a more thorough version of the stellar-core /info endpoint's fail-at
property, since the built-in version doesn't handle propagation of failures.
The algorithm will return an array of HaltingFailures, which have arrays of vulnerableNodes
(the nodes which can go down and take our network with it) and affectedNodes
(the nodes which get taken down along the way.
import { haltingAnalysis, NetworkGraphNode } from "@stellar/halting-analysis"
const nodes : NetworkGraphNode[] = await getJSON("http://stellar-core-host:11626/quorum?transitive=true&fullnodes=true"
// Search for any single node which could cause our network to halt if it goes down
const failures : HaltingFailure[] = haltingAnalysis(nodes, 1)
// Search for any combination of up to 3 nodes which could cause our node to halt if they all failed
const failures = haltingAnalysis(nodes, 3)
// Represents a failure case where a set of N nodes can take down your network
type HaltingFailure = {
// The nodes which can go down and cause havoc
vulnerableNodes: NetworkGraphNode[];
// The nodes which will go down in response to the vulnerable nodes
affectedNodes: NetworkGraphNode[];
};
// A QuorumSetGroup can be either a grouping of validators as a single
// quorum set, or a group of inner quorum sets
export type QuorumSet = {
// Threshold, the number of validators that need to agree
readonly t: number;
// List of validators or subquorum sets
readonly v: (string | QuorumSet)[];
};
export type NetworkGraphNode = {
// How far that node is from the root node (ie. how many quorum set hops)
// 0 means this is the node being administrated
readonly distance: number;
// The latest ledger sequence number that this node voted at
readonly heard?: number;
// The identity of the validator
readonly node: string;
// Quorum set. Missing or unknown nodes will be undefined.
readonly qset?: QuorumSet;
// one of behind|tracking|ahead (compared to the root node) or missing|unknown (when there are no recent SCP messages for that node)
readonly status: "behind" | "tracking" | "ahead" | "missing" | "unknown";
// what the node is voting for
readonly value?: string;
// a unique ID for what the node is voting for (allows to quickly tell if nodes are voting for the same thing)
readonly value_id?: number;
};
FAQs
Run halting analysis algorithms on stellar quorums
The npm package @stellar/halting-analysis receives a total of 1 weekly downloads. As such, @stellar/halting-analysis popularity was classified as not popular.
We found that @stellar/halting-analysis demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.