
Research
5 Malicious Chrome Extensions Enable Session Hijacking in Enterprise HR and ERP Systems
Five coordinated Chrome extensions enable session hijacking and block security controls across enterprise HR and ERP platforms.
blind-peer
Advanced tools
Blind peers help keep hypercores available.
For the client side responsible for requesting cores be kept by Blind Peers, see blind-peering.
To run the server as a CLI, see blind-peer-cli.
npm install blind-peer
to run a blind-peer server, use blind-peer-cli.
To talk to a blind peer, use blind-peering
Here is an example:
import BlindPeering from 'blind-peering'
import Hyperswarm from 'hyperswarm'
import Corestore from 'corestore'
import Wakeup from 'protomux-wakeup'
const store = new Corestore(Pear.config.storage)
const swarm = new Hyperswarm()
const wakeup = new Wakeup()
const DEFAULT_BLIND_PEER_KEYS = ['es4n7ty45odd1udfqyi9xz58mrbheuhdnxgdufsn9gz6e5uhsqco'] // replace with your own key
const blind = new BlindPeering(swarm, store, { wakeup, mirrors: DEFAULT_BLIND_PEER_KEYS })
// Add your autobase
blind.addAutobaseBackground(autobase1)
// Add another core
blind.addCore(core1, autobase1.wakeupCapability.key)
Related services:
https://github.com/holepunchto/autobase-discovery https://github.com/HDegroote/dht-prometheus
const BlindPeer = require('blind-peer')
Apache-2.0
FAQs
Blind peers help keep hypercores available
We found that blind-peer demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Five coordinated Chrome extensions enable session hijacking and block security controls across enterprise HR and ERP platforms.

Research
Node.js patched a crash bug where AsyncLocalStorage could cause stack overflows to bypass error handlers and terminate production servers.

Research
/Security News
A malicious Chrome extension steals newly created MEXC API keys, exfiltrates them to Telegram, and enables full account takeover with trading and withdrawal rights.