
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Background interface, software interface, mobile phone APP interface operation library.
Quickly and easily create a beautiful console interface.
Load the module loader first, and then load it using the module loader.
index.html
<script src="https://cdn.jsdelivr.net/npm/@litert/loader@3.5.8/dist/loader.min.js?path=index&npm={'clickgo':'3.16.1'}"></script>
index.js
import * as clickgo from 'clickgo';
class Boot extends clickgo.AbstractBoot {
public async main(): Promise<void> {
await clickgo.task.run('xxx');
}
}
clickgo.launcher(new Boot());
After installing with NPM, you'll get code hints.
$ npm i clickgo --save-dev
ClickGo demand loading Vue, jszip, resize-observer, but DO NOT reference these JS and CSS files. ClickGo will automatically reference. You only need to import "clickgo" module.
Clone and visit "dist/test/index.html".
This library is published under Apache-2.0 license.
Empty icons created by Ghozi Muhtarom - Flaticon
Empty icons created by Ghozi Muhtarom - Flaticon
No photo icons created by kerismaker - Flaticon
Identity icons created by Ghozi Muhtarom - Flaticon Truck icons created by Freepik - Flaticon
Minus SVG Vector
Copy SVG Vector
Border Radius SVG Vector
Close SVG Vector
Plus SVG Vector Trash SVG Vector
Play SVG Vector
Pause SVG Vector
Border Radius SVG Vector
Copy SVG Vector
Siderbar SVG Vector
Sort By Alphabet SVG Vector
Notification Unread Lines SVG
Bolt SVG Vector
Question Circle SVG Vector
Info Circle SVG Vector
Folder SVG Vector
File SVG Vector
Bold SVG Vector
Italic SVG Vector
FAQs
Background interface, software interface, mobile phone APP interface operation library.
The npm package clickgo receives a total of 5 weekly downloads. As such, clickgo popularity was classified as not popular.
We found that clickgo demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.