
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
[CypherWeb] aims to deliver a unified, seamless development experience influenced by Ethereum's Web3 implementation. We have taken the core ideas and expanded upon it to unlock the functionality of CYPHER's unique feature set along with offering new tools for integrating DApps in the browser, Node.js and IoT devices.
Project scope
Any new CYPHER feature will be incorporated into CypherWeb. Changes to the API to improve quality-of-life are in-scope for the project. We will not necessarilly maintain feature parity with Web3.js going forward as this is a separate project, not a synchronized fork.
You can access either version specifically from the dist folder.
CypherWeb is also compatible with frontend frameworks such as:
You can also ship CypherWeb in a Chrome extension.
npm install cypherweb
Then easiest way to use CypherWeb in a browser is to install it as above and copy the dist file to your working folder. For example:
cp node_modules/cypherweb/dist/CypherWeb.js ./js/cypherweb.js
so that you can call it in your HTML page as
<script src="./js/cypherweb.js"><script>
This project is also published on NPM and you can access CDN mirrors of this release (please use sub-resource integrity for any <script> includes).
First off, in your javascript file, define CypherWeb:
const CypherWeb = require('cypherweb')
When you instantiate CypherWeb you can define
you can also set a
which works as a jolly. If you do so, though, the more precise specification has priority.
const cypherWeb = new CypherWeb({
fullNode: 'https://some-node.tld',
solidityNode: 'https://some-other-node.tld',
eventServer: 'https://some-event-server.tld',
privateKey: 'your private key'
}
)
FAQs
JavaScript SDK that encapsulates the CYPHER HTTP API
We found that cypherweb demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.