
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
buildship-tools
Advanced tools
create-mcp-server
: Given a list of tools (workflows), it will generate a MCP server. The typescript MCP server can either forward the request to BuildShip's server or call a function. The function is a best effort translation of the BuildShip workflow that is designed to run locally without any dependencies.
export-as-function
: Given a list of workflows, it will convert those workflows into functions. The functions are a best effort translation of the BuildShip workflow that is designed to run locally without any dependencies.
Example:
npm run dev -- create-mcp-server --project buildship-qmvx2m --flows fTHAnQQmDBzMRg0jfjxS --apiKey 390fca1af5ff97df3475ecf44e7847d8255b6ef122b79ced14d46528dd2b183f --proxy --client claude
FAQs
CLI application with Google authentication
The npm package buildship-tools receives a total of 3 weekly downloads. As such, buildship-tools popularity was classified as not popular.
We found that buildship-tools demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.