
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
beam-emoticons
Advanced tools
[](https://travis-ci.org/mixer/emoticons) [](https://gitter.im/WatchBeam/developers)
This repo is used for storage of all emoticon packs that are available on Mixer. If you'd like to create and sell an emoticon pack, open a pull request to this repo. Your pull request should consist of:
index.json
in that subdirectory. See below.Running npm test
will tell you if there are any errors with your pack. Please make sure you have rsvg-convert
installed to build the pack. (librsvg2-bin
on Ubuntu)
The index.json describes your emoticon pack to us. It can contain the following sections and subsections:
":)": "smile"
would cause smile.svg
to be displayed in place of :)
. Emoticon codes must not contain spaces, <
, or >
symbols.Every emotion in this pack is copyright by their respective owners, as indicated in their index.json
. By submitting a pull request to this repository, you acknowledge that you own or have rights to distribute and sublicense the emoticons, and that your content does not infringe upon the intellectual property rights of a third party. By opening a pull request you understand that, while maintaining copyright, you grant Microsoft a non-exclusive, transferable, sub-licensable, royalty-free, worldwide license to use the contents of your pull request on the Mixer website (https://mixer.com) and that of related services.
FAQs
[](https://travis-ci.org/mixer/emoticons) [](https://gitter.im/WatchBeam/developers)
The npm package beam-emoticons receives a total of 4 weekly downloads. As such, beam-emoticons popularity was classified as not popular.
We found that beam-emoticons demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.