
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Extendable metric collector for node cluster inspired by node-millenium by Alexander Shtuchkin
Inspired by stats collection module from Node.js 1 million HTTP Comet connections test by Alexander Shtuchkin
npm install --save clumon
In every process (master or worker) attach module
var metrics = require('clumon');
In master, use collector
property to access collector instance
var collector = metrics.collector;
Listen to data
event on it and get collected stats
collector.on('data', function(frame) {
// ...
});
TODO add frame sample
TODO
You can create a monitoring server using metrics.server()
. Net.Server
instance is returned.
var server = metrics.server();
server
.listen(8000)
.on('error', function(e) {
// handle errors
});
This is a raw socket server. Then connected, it began to dump screens of text until connection is closed:
# nc monitoring.host.tld 8000
TODO Add screen sample
FAQs
Extendable metric collector for node cluster inspired by node-millenium by Alexander Shtuchkin
The npm package clumon receives a total of 2 weekly downloads. As such, clumon popularity was classified as not popular.
We found that clumon demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.