Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
magic-wormhole
Advanced tools
magic-wormhole is a project to let you send files easily and securely between computers.
This is an npm package which provides easy access to magic-wormhole, using binaries from the Go implementation (wormhole-william).
This project is UNOFFICIAL: it is not associated with either the main magic-wormhole project or with wormhole-william.
Running npx magic-wormhole send file.zip
will prepare file.zip
to be sent, and will print a "wormhole code" like 7-crossover-clockwork
.
Running npx magic-wormhole recv 7-crossover-clockwork
(using the code printed out by the previous command) on a different computer will then download that file. No coordination beyond the code is necessary.
This requires a recent version (≥ 7) of npm
to be installed. If you don't already have npm
installed, you will probably find it easier to download a binary from wormhole-william directly.
This project can interoperate with magic-wormhole and wormhole-william, so if one computer already has one of those set up, you don't need to use this package on that machine.
Each supported platform has a seperate npm package which specifies os/cpu it supports in its package.json
. All such packages are listed as optional dependencies of this package. Assuming you're using a recent version of npm
, it should download only the dependency which matches your platform, and the shim will execute it.
This approach was copied from esbuild, though esbuild goes to considerably greater lengths to support unusual situations.
You'll need to have node
and go
installed, and you will need wormhole-william cloned to a sibling of this directory (or modify the WILLIAM_DIR
variable in build.js.
Then run node build.js
to build everything. That will create package.json
and platforms.json
in this directory, and a build/
subdirectory containing all the various per-platform packages.
FAQs
magic-wormhole packaged for distribution with npm
We found that magic-wormhole demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.