
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
[](https://www.npmjs.com/package/ton)
Cross-platform client for TON blockchain.
yarn add @ton/ton @ton/crypto @ton/core buffer
// Add before using library
require("buffer");
To use this library you need HTTP API endpoint, you can use one of the public endpoints:
import { TonClient, WalletContractV4, internal } from "@ton/ton";
import { mnemonicNew, mnemonicToPrivateKey } from "@ton/crypto";
// Create Client
const client = new TonClient({
endpoint: 'https://toncenter.com/api/v2/jsonRPC',
});
// Generate new key
const mnemonic = await mnemonicNew();
const keyPair = await mnemonicToPrivateKey(mnemonic);
// Create wallet contract
const wallet = WalletContractV4.create({
workchain: 0, // basechain
publicKey: keyPair.publicKey,
});
const contract = client.open(wallet);
// Get balance
const balance = await contract.getBalance();
// Create a transfer
const seqno = await contract.getSeqno();
const transfer = await contract.createTransfer({
seqno,
secretKey: keyPair.secretKey,
messages: [internal({
value: '1.5',
to: 'EQCD39VS5jcptHL8vMjEXrzGaRcCVYto7HUn4bpAOg8xqB2N',
body: 'Hello world',
})]
});
We use biome as our formatter. It's prettier compatible and fast
yarn run format
By default tests are running using multiple worker threads. It's faster, but
undesirable during debugging. SINGLETHREADED env variable covers this case
SINGLETHREADED=1 yarn run test
We use test coverage to eliminate blind spots in our tests.
The goal is to make all functions runned at least once
yarn run coverage
Coverage report is build to the /coverage directory
Open /coverage/index.html to check the report
This library is developed by the Whales Corp. and maintained by Dan Volkov.
MIT
FAQs
[](https://www.npmjs.com/package/ton)
The npm package @ton/ton receives a total of 176,175 weekly downloads. As such, @ton/ton popularity was classified as popular.
We found that @ton/ton demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.