Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
cli-messenger
Advanced tools
A tool that provides an interface for owning your own chats.
npm i -g cli-messenger
or yarn add global cli-messenger
npm install
in this directorynpm run link
cli-messenger
NGROK=true cli-messenger
. Inspect the terminal for the ngrok addresscli-messenger connect
in a separate terminal.cli-messenger connect <server-address>
PORT=4000 cli-messenger
will run the chat server on port 4000
NGROK=true cli-messenger
will port forward the chat server to ngrok.ioDISPLAY_NAME=Mykeels cli-messenger connect
will set my chat display name to Mykeels
SILENT=true cli-messenger connect
will prevent playing notification soundsMESSAGE_SOUND_FILE=/Users/mykeels/music/my-sound.mp3 cli-messenger connect
will play my-sound.mp3
everytime a message is receivedFor developers, you should copy the
.env.example
file to a.env
file, so you can set the variables within it in bulk
In the chat client, there are commands to control the user's experience. Every command is prefixed with dot (.), so
.help
will show all available commands and their usage information.list
will list all users available in the chat.name <name>
will change your chat display name.file
will open a file dialog window, so you can select a file to sendFAQs
Start a chat session in your terminal
We found that cli-messenger demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.