
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Simple CLI tool to convert a string to bytes32
for Ethereum. Always works in reverse if given a valid bytes32 input
$ npx bytes32
0x0000000000000000000000000000000000000000000000000000000000000000
$ npx bytes32 sETH
0x7345544800000000000000000000000000000000000000000000000000000000
$ npx bytes32 Something\ With\ Spaces
0x536f6d657468696e672057697468205370616365730000000000000000000000
$ npx bytes32 Supercalifragilisticexpialidocious
Error: Input string is too long, must be maximum of 32. It is currently 34
$ npx bytes32 Supercalifragilisticexpialidocious --ignore-length
0x537570657263616c6966726167696c697374696365787069616c69646f63696f7573
$ npx bytes32 0x7345544800000000000000000000000000000000000000000000000000000000
sETH
$ npx bytes32 7345544800000000000000000000000000000000000000000000000000000000
sETH
To copy to clipboard on a mac, you can pipe to
pbcopy
.$ npx bytes32 sETH | pbcopy
or in code:
const bytes32 = require('bytes32');
console.log(bytes32({ input: 'sETH' }));
// 0x7345544800000000000000000000000000000000000000000000000000000000
console.log(bytes32({ input: 'Supercalifragilisticexpialidocious', ignoreLength: true }));
// 0x537570657263616c6966726167696c697374696365787069616c69646f63696f7573
console.log(bytes32({ input: '0x7345544800000000000000000000000000000000000000000000000000000000' }));
// sETH
FAQs
Simply utility to convert string to bytes32
The npm package bytes32 receives a total of 6,960 weekly downloads. As such, bytes32 popularity was classified as popular.
We found that bytes32 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.