
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
husky-talisman
Advanced tools
Update 2021-11-03: I wrote this over 3 years ago in while on a very security-strict client. I'm glad that this has seen some use and that there is still a demand.
I still believe there is a need for a node-wrapped taliman package with zero dependencies. I will update this package shortly. In the meanwhile node-talisman may offer some relief, although it's obviously not acceptable for zero-dependecy environments.
NOTE: this package doesn't actually require husky to run, but plans full support.
This is an npm package that downloads and sets up Thoughtwork's talisman tool for use in your node project.
The following is recommended to keep compatibility across various OS's.
If you have a preferred method feel free to use it.
Add package
npm install --save-dev husky-talisman
Add a script to package.json
{
"scripts" : {
"husky-talisman": "husky-talisman",
...
}
...
}
Add githook
Run the following via your githook tool
npm run husky-talisman [pre-commit|pre-push]
Alternatively add to your husky githooks in your package.json
or .huskyrc
file.
{
...
"husky": {
"hooks": {
...
"pre-commit": "npm run husky-talisman -- pre-commit",
"pre-push": "npm run husky-talisman -- pre-push"
}
}
}
FAQs
Allow running of the ThoughtWorks Talisman tool via node
The npm package husky-talisman receives a total of 525 weekly downloads. As such, husky-talisman popularity was classified as not popular.
We found that husky-talisman demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.