
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
nact ⇒ node.js + actors
your services have never been so µ
Any and all feedback, comments and suggestions are welcome. Please open an issue if you find anything unclear or misleading in the documentation.
This is the repository for the javascript implementation. To view/contribute to the ReasonML code, go to http://github.com/ncthbrt/reason-nact. To contribute to the documentation, https://github.com/ncthbrt/nact.io is the place to make PRs.
Servers today are very different from those even 10 years ago. So why are we still programming like it's the 90s?
Inspired by the approaches taken by Akka and Erlang, Nact is an open source Node.js framework which enables you to take control of your state to:
With out of the box support for event sourcing, and a considered implementation of the actor model, nact can work across a wide variety of domains.
Nact is no silver bullet, but it is evolving to tackle ever more demanding use cases. Perhaps one of them is yours?
To get started, head to https://nact.xyz
Note: Nact currently only able to work on Node 8 and above.
Nact sees daily usage by the project maintainer. The project is extremely stable and has been around for a few years. As the project made the deliberate choice to minimise dependencies, particularly runtime dependencies, there is not a huge need for updates to the project, besides for the occasional introduction of new features. This means that it can be a few months since the last commit. This does not mean the project is dead, but rather that it is working as designed.
We would love to hear how you're using Nact. If you'd like to send feedback (bad or good) please email Natalie Cuthbert at github@ncthbrt.com or join the Discord.
FAQs
nact ⇒ node.js + actors = your services have never been so µ
The npm package nact receives a total of 410 weekly downloads. As such, nact popularity was classified as not popular.
We found that nact demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.