
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Easily read and manipulate JSON
npm install -g cob
cat package.json | cob -g bin.cob
outputs
"./bin.cob.js"
cob -i package.json -s description='"this module is dumb"'
outputs
...
"description": "this module is dumb"
...
--input, -i, -f <file>
Read from input <file>
--output, -o <file>
Output to <file>
--get, -g <dotpath>
Return the value at <dotpath>
--set, -s <dotpath>=<value>
Set the value at <dotpath>
Extra arguments not specified by a flag will be considered either a get or a set based on the presence or lack thereof of an equal sign.
For example, cob name
is equivalent to cob --get name
and
cob name='"dummy"'
is the same as doing cob --set name='"dummy"'
.
var cob = require('cob')
and use it as so:
cob()
a through stream that pretty prints the JSON you throw at it
cob('dot.paths') || cob(['dot.paths', 'a.plenty'])
a through stream that returns newline separated values of each dotpath resolved in the JSON you throw at it
cob({'dot.path': "new value", 'a.plenty': true})
a through stream that outputs all your JSON with the changes made as specified
MIT
FAQs
read and manipulate json
The npm package cob receives a total of 1 weekly downloads. As such, cob popularity was classified as not popular.
We found that cob demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.