
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
dcent-provider
Advanced tools
This package is ethereum web3 provider of D'CENT Biometric Wallet.
It is the wrapping package communicating with dcent-web-connector
. Since dcent-web-connector
can be used only on desktop environment via USB interface, this package only for desktop environment.
npm i dcent-provider
import DcentProvider from 'dcent-provider'
const provider = new DcentProvider({
rpcUrl: "YOUR_RPC_URL", // required
chainId: 1, // (optional) default = 1
})
const account = await provider.enable()
const tx = {
from: account[0],
gasPrice: "2000000000",
gas: "21000",
to: account[0],
value: "0",
data: ""
}
const receipt = await provider.send('eth_sendTransaction', tx)
import Web3 from 'web3'
import DcentProvider from 'dcent-provider'
const provider = new DcentProvider({
rpcUrl: "YOUR_RPC_URL", // required
chainId: 1, // (optional) default = 1
})
const web3 = new Web3(provider)
const accounts = await web3.eth.getAccounts()
const tx = {
from: accounts[0],
gasPrice: "2000000000",
gas: "21000",
to: account[0],
value: "0",
data: ""
}
const receipt = await web3.eth.sendTransaction(tx)
Check example package
npm run build
npm run build-dev
npm run test
FAQs
D'CENT Provider wrapping Dcent Web Connector
We found that dcent-provider demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.