
Research
Security News
Malicious npm Packages Use Telegram to Exfiltrate BullX Credentials
Socket uncovers an npm Trojan stealing crypto wallets and BullX credentials via obfuscated code and Telegram exfiltration.
This CLI provides tooling/commands to assist you in the scenes development process. Some of the commands will help you scaffold a new scene project, locally start and visualize the scene in order to test it and deploy it to a content server to be incorporated in your Decentraland parcel.
To install the latest version of dcl
(Decentraland CLI), run this command:
npm install -g decentraland
To learn what you can do with the CLI run the following command:
dcl --help
See more details at Decentraland docs.
For details on how to use Decentraland developer tools, check our documentation site
npm install
.npm run build
.npm link
. The dcl
command should now be available.npm test
NOTE: you can set the environment variable DEBUG=true
to see all debugging info
Just update the version on the package.json
file and merge to master.
dcl
can be configured in several ways to adapt it to another environment other than the default one. To do this you have to either set environment variables or change your ~/.dclinfo
file:
Variable name | Enviroment variable | ~/.dclinfo |
---|---|---|
Provider | RPC_URL | - |
MANA Token Contract | MANA_TOKEN | MANAToken |
LAND Registry Contract | LAND_REGISTRY | LANDRegistry |
Estate Registry Contract | ESTATE_REGISTRY | EstateRegistry |
Content Server URL | CONTENT_URL | contentUrl |
Segment API key | SEGMENT_KEY | segmentKey |
Track Analytics data | TRACK_STATS | trackStats |
This repository is protected with a standard Apache 2 license. See the terms and conditions in the LICENSE file.
FAQs
Decentraland CLI developer tool.
The npm package decentrand receives a total of 5 weekly downloads. As such, decentrand popularity was classified as not popular.
We found that decentrand demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket uncovers an npm Trojan stealing crypto wallets and BullX credentials via obfuscated code and Telegram exfiltration.
Research
Security News
Malicious npm packages posing as developer tools target macOS Cursor IDE users, stealing credentials and modifying files to gain persistent backdoor access.
Security News
AI-generated slop reports are making bug bounty triage harder, wasting maintainer time, and straining trust in vulnerability disclosure programs.