Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
This directory contains the TypeScript codebase. There are several different build targets produced by the same codebase. Some targets build for a browser environment; some build for a node environment.
src/browser/
contains code that is only intended to run in the
browser.
src/node/
contains code that is only intended to run in node.js.
src/iso/
contains code that is intended to run in either node.js or
the browser.
One key exception to this rule is that unit tests are always running in node.js, albeit from a Jest environment that is mimicking the browser.
TypeScript will store its build files in /build/
, and Parcel will
store its build files in /dist/
. You can ignore these directories
unless you are mucking around with the build system.
The local chrome extension, used for testing against a blockchain
running on your machine, is built into /ext-local/
with the command
npm run ext-local
.
The CLI is run as a Node application via npm run cli
.
The hosting server is run as a Node application via npm run hserver
.
There is an app used for testing things, built into /app/
with the
command npm run app
. You don't really need this; it's just handy to
use as a testbed sometimes.
./start-local.sh
npm install
npm run ext-local
chrome://extensions
axiom/ts/ext-local
directorynpm run hserver
npm run cli create-bucket
FAQs
API for interacting with the Axiom.org platform
The npm package axiom-api receives a total of 6 weekly downloads. As such, axiom-api popularity was classified as not popular.
We found that axiom-api demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.