
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
hack-spirit
Advanced tools
hack-spirit is a client library and a cli for TeamSpirit. It makes TeamSpirit hackable.
Currently, it provides these functionalities:
$ npm install --global https://github.com/aHirokiKumamoto/hack-spirit
I strongly recommend login
command that stores your credentials.
You don't need to put the options --user
and --password
when once you login.
Usage: hack-spirit [options] [command]
Commands:
login login with your team sprint credentials
work_status print current work status
start_work start work
finish_work finish_work
overtime [options] Report your overtime work
delayed [options] Report your delayed arrival
worktime [options] Record worktime
chill_out [options] Chill out
chilled_out [options] Chilled out until the time
chills [options] Manage a chills
weekly [options] Generate weekly worktime report
monthly [options] Generate weekly worktime report
time_report [options] Generate worktime report with a specified period
Options:
-h, --help output usage information
-V, --version output the version number
-u, --user [String] user name
-p, --password [String] password
-v, --verbose print log
-b, --browser show browser
Some command (such as overtime
) takes extra options.
Please run hack-spirit [command] --help
and check out the output
$ hack-spirit work_status -u user_name -p password
hack-spirit is highly depended on [nightmare][] that uses [electron][] as headless browser.
So, you can see how the electron works with --browser
options.
[nightmare]: https://github.com/segmentio/nightmare) [electron]: http://electron.atom.io/
FAQs
Make TeamSpirit hackable
We found that hack-spirit demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.