
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
@tv2media/logger
Advanced tools
The framework aims to facilitate the logging needs of the developers in TV2 Media Technology, as well as creating an uniform logging strategy across Typescript and Javascript projects.
The package can be installed by:
$ yarn add @tv2media/logger
To build from source:
$ git clone https://github.com/tv2/mediatech-logger.git
$ cd mediatech-logger
$ yarn && yarn build
import { createDefaultLogger } from '@tv2media/logger'
const logger = createDefaultLogger()
logger.info('Server started.')
logger.error('Request failed.')
logger.data(new Error('Some dangerous error!')).error('Request failed.')
import {
Logger, // The base class Logger for custom configuration.
createDefaultLogger, // Returns an instance of one of the following loggers based upon NODE_ENV.
ProductionLogger, // Logger used in production.
StagingLogger, // Logger used in staging.
DevelopmentLogger, // Logger used in development.
LocalLogger, // Logger used in local development.
LogLevel, // The severity of the
Format, // Formatting type of the log
Vault, // Where to store logs
} from '@tv2media/logger'
const logger = new Logger({
level: LogLevel.Info, // .Error | .Warn | .Info | .Debug | .Trace
format: {
kind: Format.Custom // .Plaintext | .JSON | .Custom
format: (log, options) => { // Only used for .Custom, and is custom format.
let out = '[' + log.level + ']'
if (options.timestamp) {
out += '[' + new Date().toString() + ']'
}
return out + ' ' + data.message
},
timestamp: true, // Whether or not to include timestamp.
depth: 3n, // Depth to traverse in objects. Default is -1n (full depth).
},
vault: { // Where to store logs
kind: Vault.Console, // .Console
},
})
logger.data('some-data') // Adds the key-value pair { "data": "some-data" } to a new log context.
logger.tag('some-tag') // Adds the key-value pair { "tag": "some-tag" } to a new log context.
logger.error('Sever failed.') // Stores a log context with severity level of 'error'.
logger.warn('No response from client.') // Stores a log context with severity level of 'warn'.
logger.info('Server started at ip:port') // Stores a log context with severity level of 'info'.
logger.debug({ ip: '0.0.0.0' }) // Stores a log context with severity level of 'debug'.
logger.info('some trace here') // Stores a log context with severity level of 'trace'.
logger.tag('testing').info('test message')
logger.info('message', { tag: 'testing', otherMeta: 'meta' }) // Each of the severity level methods takes an optional argument, with extra attributes for the log context.
The createDefaultLogger is using the environment variable NODE_ENV to determine which log level and format which will be used. The current setup is the following.
NODE_ENV=production # fomat = JSON, log level = warn
NODE_ENV=stage | staging # format = JSON, log level = info
NODE_ENV=develop | development # fomat = PLAINTEXT, log level = debug
NODE_ENV=local # fomat = PLAINTEXT, log level = trace
NODE_ENV="any other value" # fomat = PLAINTEXT, log level = trace
Setting the environment variable LOG_LEVEL overrides the log level from the NODE_ENV setup, this can come in handy when you need to enable e.g. debugging logs in a production enviorment.
function getLogLevel(): LogLevel | undefined {
switch (process.env.LOG_LEVEL?.toLowerCase()) {
case 'error': return LogLevel.Error
case 'warn': return LogLevel.Warn
case 'info': return LogLevel.Info
case 'debug': return LogLevel.Debug
case 'trace': return LogLevel.Trace
default: return undefined
}
}
FAQs
Unknown package
We found that @tv2media/logger demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.