Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
This is a small library to encode and decode bencoded (bittorrent) stuff. Bencoding is specified here.
github repository is here
Installable via npm (npm package name is bncode, note spelling!):
npm install bncode
Encoding works as follows:
var benc = require("bncode"),
exmp = {}
exmp.bla = "blup"
exmp.foo = "bar"
exmp.one = 1
exmp.woah = {}
exmp.woah.arr = []
exmp.woah.arr.push(1)
exmp.woah.arr.push(2)
exmp.woah.arr.push(3)
exmp.str = new Buffer("Buffers work too")
var bencBuffer = benc.encode(exmp)
// d3:bla4:blup3:foo3:bar3:onei1e4:woahd3:arr \
// li1ei2ei3eee3:str16:Buffers work tooe
Decoding will work progressively, e.g. if you're receiving partial bencoded strings on the network:
var benc = require("bncode"),
buf = null
decoder = new benc.decoder()
while (buf = receiveData()) {
decoder.decode(buf)
}
log(decoder.result())
Or "all in one"
var benc = require("bncode"),
buf = getBuffer(),
dec = benc.decode(buf)
log(dec.bla)
There are some subtleties concerning bencoded strings. These are decoded as Buffer objects because they are just strings of raw bytes and as such would wreak havoc with multi byte strings in javascript.
The exception to this is strings appearing as keys in bencoded dicts. These are decoded as Javascript Strings, as they should always be strings of (ascii) characters and if they weren't decoded as JS Strings, dict's couldn't be mapped to Javascript objects.
+----------------------------------------------------+
| | |
| Bencoded | Javascript |
|====================================================|
| Strings | node Buffers, unless they are |
| | Dictionary keys, in which case |
| | they become Javascript Strings |
|----------------+-----------------------------------|
| Integers | Number |
|----------------+-----------------------------------|
| Lists | Array |
|----------------+-----------------------------------|
| Dictionaries | Object |
| | |
+----------------------------------------------------+
The code makes a best effort to encode Javascript to bencoding. If you stick to basic types (Arrays, Objects with String keys and basic values, Strings, Buffers and Numbers) you shouldn't encounter suprises. Expect surprises (mainly not being able to round-trip encode/decode) if you encode fancy data-types.
bncode was written by Tim Becker (tim.becker@kuriositaet.de) I can be reached via email or (preferably) submit a bug to the github repository.
MIT, see LICENSE
FAQs
bittorrent bencoding and decoding.
The npm package bncode receives a total of 363 weekly downloads. As such, bncode popularity was classified as not popular.
We found that bncode demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.