
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@tryvital/vital-node
Advanced tools
[](https://www.npmjs.com/package/@tryvital/vital-node) [](https://github.com/fern-api/fern)
The Vital Node.js library provides access to the Vital API from JavaScript/TypeScript.
API reference documentation is available here.
npm install --save @tryvital/vital-node
# or
yarn add @tryvital/vital-node
import { VitalClient, VitalEnvironment } from '@tryvital/vital-node';
const vital = new VitalClient({
apiKey: 'YOUR_API_KEY',
});
const labTest = await vital.labTests.get('order-id');
console.log('Received lab test', labTest);
Please note: To ensure future compatibility, we ask that you avoid exhaustive matching on enum values such as an order’s status. We may introduce new statuses (and other enum values) over time, and code that assumes all current values are exhaustive could break or fail to compile with SDK upgrades.
To stay compatible and benefit from future enhancements, treat unknown values gracefully—for example, by using default cases or limiting checks to only the values your integration depends on.
When the API returns a non-success status code (4xx or 5xx response), a subclass of VitalError will be thrown:
try {
await vital.labTests.get('order-id');
} catch (err) {
if (err instanceof VitalError) {
console.log(err.statusCode);
console.log(err.message);
console.log(err.body);
}
}
When you sign up to Vital you get access to two environments, Sandbox and Production.
Environment URLs | |
---|---|
production | api.tryvital.io |
production-eu | api.eu.tryvital.io |
sandbox | api.sandbox.tryvital.io |
sandbox-eu | api.sandbox.eu.tryvital.io |
By default, the SDK uses the production
environment. See the snippet below
for an example on how ot change the environment.
import { VitalClient, VitalEnvironment } from '@tryvital/vital-node';
const vital = new VitalClient({
apiKey: 'YOUR_API_KEY',
environmment: VitalEnvironment.Sandbox,
});
Each method in the SDK accepts an additional optional parameter where you can specify request options such as a timeout.
const labTest = await vital.labTests.get('order-id', {
timeoutInSeconds: 40 // wait 40 seconds for this call
});
This SDK is in beta, and there may be breaking changes between versions without a major version update. Therefore, we recommend pinning the package version to a specific version in your package.json file. This way, you can install the same version each time without breaking changes unless you are intentionally looking for the latest version.
While we value open-source contributions to this SDK, this library is generated programmatically. Additions made directly to this library would have to be moved over to our generation code, otherwise they would be overwritten upon the next generated release. Feel free to open a PR as a proof of concept, but know that we will not be able to merge it as-is. We suggest opening an issue first to discuss with us!
On the other hand, contributions to the README are always very welcome!
FAQs
[](https://www.npmjs.com/package/@tryvital/vital-node) [](https://github.com/fern-api/fern)
We found that @tryvital/vital-node demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.