
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Self-hosted analytics for After Dark. Voyeur adds support for Fathom Analytics.
For Voyeur to operate you must have Fathom up and running on a VPS or embedded device such as ODROID or Raspberry Pi. If your domain uses TLS you must also enable TLS on your Fathom domain for reporting to function. If you have a wildcard SSL cert on your existing domain consider hosting Fathom on a subdomain such as stats.example.com
for certificate reuse.
An example Docker Compose file to run Fathom using a Postgres database has been provided to you here as a convenience. Instructions on using it are beyond the scope of this module.
Copy the contents of this repository into a directory called themes/voyeur
under the root your After Dark site.
Add voyeur
as a theme component to your After Dark site config.toml
, e.g.
theme = [
"voyeur", # sequence before "after-dark"
"after-dark"
]
Add and specify settings for the module in your After Dark site config, e.g.
[params.modules.voyeur]
enabled = true # Optional, set false to disable module
url = "https://stats.example.org" # Optional, base analytics URL
port = "8080" # Optional, port setting
Build and deploy your After Dark site.
For additional information please see the Fathom project.
For development, install Docker on your machine:
Configure your environment to use the dev config override:
export COMPOSE_FILE=docker-compose.yml:docker-compose.dev.yml
Run docker-compose up
to start the app.
Please squash commits and use Convention Commit messages. Run npm run commit
after installing NPM dev dependencies for help creating conventional commit messages.
Copyright (C) 2018, 2019 by Josh Habdas jhabdas@protonmail.com
Permission to use, copy, modify, and/or distribute this software for any purpose with or without fee is hereby granted.
The text of the above license is included in the file COPYING in the source.
FAQs
Fathom Analytics module for After Dark.
The npm package mod-voyeur receives a total of 3 weekly downloads. As such, mod-voyeur popularity was classified as not popular.
We found that mod-voyeur demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.