Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
cashscript
Advanced tools
CashScript is a high-level programming language for smart contracts on Bitcoin Cash. It offers a strong abstraction layer over Bitcoin Cash' native virtual machine, Bitcoin Script. Its syntax is based on Ethereum's smart contract language Solidity, but its functionality is very different since smart contracts on Bitcoin Cash differ greatly from smart contracts on Ethereum. For a detailed comparison of them, refer to the blog post Smart Contracts on Ethereum, Bitcoin and Bitcoin Cash.
See the GitHub repository and the CashScript website for full documentation and usage examples.
CashScript is a high-level language that allows you to write Bitcoin Cash smart contracts in a straightforward and familiar way. Its syntax is inspired by Ethereum's Solidity language, but its functionality is different since the underlying systems have very different fundamentals. See the language documentation for a full reference of the language.
The main way to interact with CashScript contracts and integrate them into applications is using the CashScript SDK. This SDK allows you to import .json
artifact files that were compiled using the cashc
compiler and convert them to Contract
objects. These objects are used to create new contract instances. These instances are used to interact with the contracts using the functions that were implemented in the .cash
file. For more information on the CashScript SDK, refer to the SDK documentation.
npm install cashscript
import { Contract, ... } from 'cashscript';
const { Contract, ... } = require('cashscript');
Using the CashScript SDK, you can import contract artifact files, create new instances of these contracts, and interact with these instances:
...
// Import the P2PKH artifact
const P2PKH = require('./p2pkh-artifact.json');
// Instantiate a network provider for CashScript's network operations
const provider = new ElectrumNetworkProvider('mainnet');
// Create a new P2PKH contract with constructor arguments: { pkh: pkh }
const contract = new Contract(P2PKH, [pkh], provider);
// Get contract balance & output address + balance
console.log('contract address:', contract.address);
console.log('contract balance:', await contract.getBalance());
// Call the spend function with the owner's signature
// And use it to send 0. 000 100 00 BCH back to the contract's address
const txDetails = await contract.functions
.spend(pk, new SignatureTemplate(keypair))
.to(contract.address, 10000)
.send();
console.log(txDetails);
...
FAQs
Easily write and interact with Bitcoin Cash contracts
The npm package cashscript receives a total of 148 weekly downloads. As such, cashscript popularity was classified as not popular.
We found that cashscript demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.