Research
Security News
Threat Actor Exposes Playbook for Exploiting npm to Build Blockchain-Powered Botnets
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
@vonage/messages
Advanced tools
Multi-channel messaging that integrates WhatsApp, Facebook, Viber, SMS, and MMS
This is the Vonage Messages SDK for Node.js for use with Vonage APIs. To use it you will need a Vonage account. Sign up for free at vonage.com.
For full API documentation refer to developer.nexmo.com.
If you are updating from V2 to V3, please check the migration guide found here
We recommend using this SDK as part of the overall @vonage/server-sdk
package. Please see the main package for installation.
You can also use this SDK standalone if you only need access to just the Messages API.
npm install @vonage/messages
yarn add @vonage/messages
If you are using this SDK as part of the Vonage Server SDK, you can access it as the messages
property off of the client that you instantiate.
const {Vonage} = require('@vonage/server-sdk');
const { Auth, AlgorithmTypes } = require('@vonage/auth');
const { SMS } = require('@vonage/messages');
const vonage = new Vonage(new Auth({
apiKey: API_KEY,
apiSecret: API_SECRET,
applicationId: APP_ID,
privateKey: PRIVATE_KEY_PATH,
signature: {
secret: 'ABCDE',
algorithm: AlgorithmTypes.md5hash,
},
}), options);
vonage.messages.send(new SMS({
to: TO_NUMBER,
from: FROM_NUMBER,
text: MESSAGE
}));
The SDK can be used standalone from the main Vonage Server SDK for Node.js
if you only need to use the Messages API. All you need to do
is require('@vonage/messages')
, and use the returned object to create your own
client.
const {Auth} = require('@vonage/auth');
const {Messages} = require('@vonage/messages');
const messagesClient = new Messages(new Auth({
apiKey: API_KEY,
apiSecret: API_SECRET,
applicationId: APP_ID,
privateKey: PRIVATE_KEY_PATH,
}), options);
Most methods that interact with the Vonage API uses Promises. You can either resolve these yourself, or use await
to
wait for a response.
const resp = await messagesClient.send(new SMS({
to: TO_NUMBER,
from: FROM_NUMBER,
text: MESSAGE
}));
messagesClient.send(new SMS({
to: TO_NUMBER,
from: FROM_NUMBER,
text: MESSAGE,
}))
.then(resp => console.log(resp))
.catch(err => console.error(err));
Run:
npm run test
The Vonage Messages API supports several different communication channels, and from time to time will add new channels. Each channel follows our normal product development cycle and therefore different channels within the overall API may have different release statuses at a certain point in time. Channels available for general use will be listed as having 'General Availability'. Channels which are currently part of a Beta program will be listed as 'Beta'. This table details the current release status of each channel implemented in this SDK:
Channel | API Release Status |
---|---|
SMS | General Availability |
MMS | General Availability |
RCS | Beta |
Facebook Messenger | General Availability |
General Availability | |
WhatsApp (reaction) | Beta |
Viber | General Availability |
FAQs
Multi-channel messaging that integrates WhatsApp, Facebook, Viber, SMS, and MMS
The npm package @vonage/messages receives a total of 32,209 weekly downloads. As such, @vonage/messages popularity was classified as popular.
We found that @vonage/messages demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
Security News
NVD’s backlog surpasses 20,000 CVEs as analysis slows and NIST announces new system updates to address ongoing delays.
Security News
Research
A malicious npm package disguised as a WhatsApp client is exploiting authentication flows with a remote kill switch to exfiltrate data and destroy files.