
Research
/Security News
DuckDB npm Account Compromised in Continuing Supply Chain Attack
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
lightsocks-nodejs
Advanced tools
一个轻量级网络混淆代理,基于 SOCKS5 协议,可用来代替 Shadowsocks。
Lightsocks 的实现原理?请阅读文章:你也能写个 Shadowsocks
NodeJS版本>=8
sudo npm install -g lightsocks-nodejs
用于运行在代理服务器的客户端,会还原混淆数据
Usage: lsserver [options]
It's a simaple socks5 proxy tool which based on lightsocks
Options:
-V, --version output the version number
-P, --password [value] the password for server
-L, --listen [value] the listen address for server
-h, --help output usage information
如果不加任何参数,默认在当前用户文件夹下生成配置文件。
用于运行在本地电脑的客户端,用于桥接本地浏览器和远程代理服务,传输前会混淆数据
Usage: lslocal [options]
It's a simaple socks5 proxy tool which based on lightsocks
Options:
-V, --version output the version number
-P, --password [value] the password for server
-L, --listen [value] the listen address for server
-R, --remote [value] the remote server address
-h, --help output usage information
FAQs
It's a simaple socks5 proxy tool which based on lightsocks
We found that lightsocks-nodejs demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Ongoing npm supply chain attack spreads to DuckDB: multiple packages compromised with the same wallet-drainer malware.
Security News
The MCP Steering Committee has launched the official MCP Registry in preview, a central hub for discovering and publishing MCP servers.
Product
Socket’s new Pull Request Stories give security teams clear visibility into dependency risks and outcomes across scanned pull requests.