
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
A chain-agnostic CLI tool for interacting with Cosmos SDK blockchains.
You can install the CLI tool globally using npm, yarn, or pnpm:
# Using npm
npm install -g cosmcli
# Using yarn
yarn global add cosmcli
# Using pnpm
pnpm add -g cosmcli
Alternatively, you can use it directly without installation using npx:
npx cosmcli <command>
Transfer tokens from one chain to another using IBC.
cosmcli ibc-transfer [options]
--rpc <rpc>: RPC URL of the source chain--seed <seed>: Seed phrase/mnemonic for the sender's wallet--prefix <prefix>: Bech32 address prefix of the source chain (e.g., "cosmos", "stride", "osmo")--gas-price <gasPrice>: Gas price per unit (e.g., "0.025uatom")--receiver <receiver>: Destination address to receive tokens--amount <amount>: Amount to transfer (e.g., "10uatom")--src-channel <srcChannel>: Source channel ID for the IBC transfer--gas-adjustment <gasAdjustment>: Gas multiplier for transaction simulation (default: "1.4")-v, --verbose: Enable verbose logging (default: false)--src-port <srcPort>: Source port for IBC (default: "transfer")--timeout <timeout>: Timeout in seconds (default: "180")--memo <memo>: Transaction memo (default: "")cosmcli ibc-transfer \
--rpc https://rpc.cosmos.network \
--seed "your mnemonic words here" \
--prefix cosmos \
--gas-price 0.025uatom \
--receiver osmo1yourosmoaddress \
--amount 10uatom \
--src-channel channel-141
On successful IBC transfer, the tool outputs a JSON object containing:
tx: Transaction hash on the source chainibcAck: IBC acknowledgement transaction hashExample output:
{ "tx": "ABC123DEF456GHI789JKL", "ibcAck": "MNO123PQR456STU789VWX" }
If an error occurs, the program will:
With the --verbose flag, additional error details and stack traces are provided.
FAQs
A chain-agnostic CLI tool for interacting with Cosmos SDK blockchains.
We found that cosmcli demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.