
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.



To install this application, you'll need Node.js 7+ (which comes with npm) installed on your computer. From your command line:
You'll need Git to run the project from source. From your command line:
# Clone this repository
$ git clone https://github.com/seanjameshan/coin-cli
# Go into the repository
$ cd coin-cli
# Install dependencies
$ npm install
# Run the app
$ npm start
$ npm install ts-node -g
$ npm install coin-ts -g
$ coin
| Command | Alias | Description | Example |
|---|---|---|---|
| open | o | Open to accept incoming connections. | open 5000 |
| connect | c | Connect to a new peer with and | connect localhost 5000 |
| blockchain | bc | See the current state of the blockchain. | |
| peers | p | Get the list of connected peers. | |
| mine [address] | m | Mine a new block with rewards going to optional [address]. | mine or mine xxx... |
| transactions | tx | See unconfirmed transactions that can be mined. | |
| wallet | w | Create a new wallet with | wallet mypassword |
| key | k | Get your public key | |
| pay | p | Make payment to with and using wallet | pay xxx... 10 5 mypassword |
| balance [address] | b | Balance of optional | balance or balance xxx... |
| help [command...] | Provides help for a given command | help balance or help | |
| exit | Exits application. |
FAQs
A minimal cryptocurrency CLI implementation in TypeScript & Immutable.js
We found that coin-ts demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.