
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
book-of-spells
Advanced tools
A collection of JavaScript functions and snippets that I use in my projects in ESM format. This is mainly for my own reference, but I hope it can be useful to others as well.
The problem, Bernard, is that what you and I do is so complicated. We practice witchcraft. We speak the right words. Then we create life itself⦠out of chaos. - Dr. Robert Ford, Westworld S01E02
npm i book-of-spells
import { clone } from 'book-of-spells' // if your bundler doesn't resolve npm packages use the full path: import { clone } from './node_modules/book-of-spells/index.mjs'
const a = { a: 1, b: 2, c: { d: 3, e: 4} }
const b = clone(a)
console.log( a.c === b.c ) // false
After 14+ years of JavaScript and copy-pasting my own undocumented code, I've decided to start documenting it. I'm not sure why I didn't do it sooner. Actually, I'm lying, I do know why. I am so lazy that I'd rather copy or write the same code over and over again than document it - which is, of course, much more work than keeping and maintaining it in one place and distributing it as a package.
It's not only laziness, if you think about it. It is this omnipresent fear of change, of the unknown, of the new. But change is good. Being unconformable is good. It means you're growing. It means you're learning. It means you're alive.
If you have a function or a snippet that you think is useful, please open a PR. I'd love to see what you've got.
With love π, Stamat
FAQs
π Stamat's Book of JavaScript Spells
The npm package book-of-spells receives a total of 356 weekly downloads. As such, book-of-spells popularity was classified as not popular.
We found that book-of-spells demonstrated a not healthy version release cadence and project activity because the last version was released a year ago.Β It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.