
Research
TeamPCP Compromises Telnyx Python SDK to Deliver Credential-Stealing Malware
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.
EVM (Ethereum Virtual Machine) implementation of the x402 payment protocol using the Exact payment scheme with EIP-3009 TransferWithAuthorization.
npm install @x402/evm
This package provides three main components for handling x402 payments on EVM-compatible blockchains:
@x402/evm)V2 Protocol Support - Modern x402 protocol with CAIP-2 network identifiers
Client:
ExactEvmClient - V2 client implementation using EIP-3009toClientEvmSigner(account) - Converts viem accounts to x402 signersClientEvmSigner - TypeScript type for client signersFacilitator:
ExactEvmFacilitator - V2 facilitator for payment verification and settlementtoFacilitatorEvmSigner(wallet) - Converts viem wallets to facilitator signersFacilitatorEvmSigner - TypeScript type for facilitator signersService:
ExactEvmServer - V2 service for building payment requirements@x402/evm/v1)V1 Protocol Support - Legacy x402 protocol with simple network names
Exports:
ExactEvmClientV1 - V1 client implementationExactEvmFacilitatorV1 - V1 facilitator implementationNETWORKS - Array of all supported V1 network namesSupported V1 Networks:
[
"abstract", "abstract-testnet",
"base-sepolia", "base",
"avalanche-fuji", "avalanche",
"iotex", "sei", "sei-testnet",
"polygon", "polygon-amoy",
"peaq", "story", "educhain",
"skale-base-sepolia"
]
@x402/evm/client)Convenience builder for creating fully-configured EVM clients
Exports:
createEvmClient(config) - Creates x402Client with EVM supportEvmClientConfig - Configuration interfaceWhat it does:
eip155:*)NETWORKSExample:
import { createEvmClient } from "@x402/evm/client";
import { toClientEvmSigner } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";
const account = privateKeyToAccount("0x...");
const signer = toClientEvmSigner(account);
const client = createEvmClient({ signer });
// Ready to use with both V1 and V2!
eip155:8453)eip155:*)base-sepolia)import { createEvmClient } from "@x402/evm/client";
import { wrapFetchWithPayment } from "@x402/fetch";
const client = createEvmClient({ signer: myEvmSigner });
const paidFetch = wrapFetchWithPayment(fetch, client);
import { x402Client } from "@x402/core/client";
import { ExactEvmClient } from "@x402/evm";
import { ExactEvmClientV1 } from "@x402/evm/v1";
const client = new x402Client()
.register("eip155:*", new ExactEvmClient(signer))
.registerSchemeV1("base-sepolia", new ExactEvmClientV1(signer))
.registerSchemeV1("base", new ExactEvmClientV1(signer));
import { x402Client } from "@x402/core/client";
import { ExactEvmClient } from "@x402/evm";
const client = x402Client.fromConfig({
schemes: [
{ network: "eip155:*", client: new ExactEvmClient(signer) },
{ network: "base-sepolia", client: new ExactEvmClientV1(signer), x402Version: 1 }
],
policies: [myCustomPolicy]
});
V2 Networks (via CAIP-2):
eip155:1 - Ethereum Mainneteip155:8453 - Base Mainneteip155:84532 - Base Sepoliaeip155:* - Wildcard (matches all EVM chains)eip155:<chainId> networkV1 Networks (simple names):
See NETWORKS constant in @x402/evm/v1
Supports any ERC-3009 compatible token:
transferWithAuthorization()# Build
npm run build
# Test
npm run test
# Integration tests
npm run test:integration
# Lint & Format
npm run lint
npm run format
@x402/core - Core protocol types and client@x402/fetch - HTTP wrapper with automatic payment handling@x402/svm - Solana/SVM implementationFAQs
x402 Payment Protocol EVM Implementation
The npm package @x402/evm receives a total of 32,253 weekly downloads. As such, @x402/evm popularity was classified as popular.
We found that @x402/evm demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.

Security News
/Research
Widespread GitHub phishing campaign uses fake Visual Studio Code security alerts in Discussions to trick developers into visiting malicious website.