
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
@universal-packages/time-based-one-time-password
Advanced tools
Time-based one-time password implementation
implementation from RFC6238
npm install @universal-packages/time-based-one-time-password
Generates the current otp password for the current time.
algorithm 'sha1' | 'sha256' | 'sha512' default: sha1
Algorithm to use when generating the hmac hash.codeDigits number default: 6
How many digits to take for the final password.time number default: Date.now() / 10000.0
Time in seconds for which the password will be generatedtimeStep number default: 30
The time window in seconds in which the password should be valid (the same).verify(subject: string, secret: string, [options])Verify if the given password is valid for the time window, in will verify the specified steps around the specified time window, basically:
|------------------|------------------|------------------|
previous current next
It will verify the current time window (or time given) and the surroundings by the given offsetSteps in the example above the offset is one. Make sure to verify password using the same options used for generating them.
Verify uses the same options as generate and additionally:
offsetSteps number default: 1
Number of steps around the given time should be tested for the verification.Some verificators require you to pass the secret in base32 format (for some reason), you can use packages like Base32 Encode, for example for the google authenticator you can do:
import base32Encode from 'base32-encode'
const base32Secret = base32Encode('secret', 'RFC4648').replace('=', '')
console.log(base32Secret)
// > Some base32 string
This library is developed in TypeScript and shipped fully typed.
The development of this library happens in the open on GitHub, and we are grateful to the community for contributing bugfixes and improvements. Read below to learn how you can take part in improving this library.
FAQs
Time-based one-time password implementation
We found that @universal-packages/time-based-one-time-password demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.