
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
larvitamintercom
Advanced tools
[](https://github.com/larvit/larvitamintercom/actions)
Communication wrapper for rabbitmq in autobahn.
When instantiating a new intercom it will try to connect instantly and on connection error or connection lost it will try to reconnect an infinite number of times every 1sec.
send() to autobahn.
const Intercom = require('larvitamintercom'),
conStr = 'amqp://user:password@192.168.0.1/',
intercom = new Intercom(conStr);
let message = {'hello': 'world'},
options = {'exchange': 'foo'}; // Will default to "default" if options is omitted
intercom.send(message, options, function (err, msgUuid) {
// called when message is accepted by queue handler
// msgUuid will be a unique UUID for this specific message
});
{
'exchange': 'default',
'durable': true,
'forceConsumeQueue': false // Will create a queue for consumtion even if there is no current listeners. This way no message will ever be lost, since they will wait in this queue until some consumer consumes them.
}
There are two types of read operations; "consume" and "subscribe".
A message can only be "consumed" once, but it can be "subscribed" several times, by different readers.
Consumers can be assigned to an exchanged after the message have been sent, and they still receive the message. However, very importantly, ONE consumer must be assigned before the send happends, or the consumer queue never gets declared!
Subscribers, in contrast, must subscribe BEFORE the message is sent or they will not receive it.
Each subscriber only get each message once.
const Intercom = require('larvitamintercom'),
conStr = 'amqp://user:password@192.168.0.1/',
intercom = new Intercom(conStr);
let options = {'exchange': 'foo'}; // Will default to "default" if options is omitted
intercom.consume(options, function (message, ack, deliveryTag) {
// message being the object sent with intercom.send()
// deliveryTag is an identification of this delivery
// Must be ran! Always! ACK!!
ack();
// or
ack(new Error('Something was wrong with the message'));
}, function (err) {
// Callback from established consume connection
});
{
'exchange': 'default'
}
const Intercom = require('larvitamintercom').Intercom,
conStr = 'amqp://user:password@192.168.0.1/',
intercom = new Intercom(conStr);
let options = {'exchange': 'default'};
intercom.subscribe(options, function (message, ack, deliveryTag) {
// message subscribe the object sent with intercom.send()
// deliveryTag is an identification of this delivery
// Must be ran! Always! ACK!!
ack();
// or
ack(new Error('Something was wrong with the message'));
}, function (err, subscribeInstance) {
// Callback from established subscribe connection
});
{
'exchange': 'default'
}
const Intercom = require('larvitamintercom').Intercom,
winston = require('winston'),
log = winston.createLogger({'transports': [new winston.transports.Console()]}),
conStr = 'amqp://user:password@192.168.0.1/',
intercom = new Intercom({'conStr': conStr, 'log': log});
The conString
can also be an array.
const Intercom = require('larvitamintercom'),
conStr = ['amqp://user:password@192.168.0.1/', 'amqp://user:password@192.168.0.2/'],
intercom = new Intercom(conStr);
FAQs
[](https://github.com/larvit/larvitamintercom/actions)
The npm package larvitamintercom receives a total of 152 weekly downloads. As such, larvitamintercom popularity was classified as not popular.
We found that larvitamintercom demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.