
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
niconizer
Advanced tools
A desktop application that displays plain text, images, or any other HTML content on the screen, like nicovideo or bilibili.
niconizer is a simple desktop application that has two functionalities below.
It can be used in combination with clients that send contents.
$ npm i -g niconizer
$ niconizer
Then the WebSocket server starts up on your computer and listens for connections.
Available clients are in the section bellow.
Start
Stop
Quit
Currently, no authentication is implemented.
// WebSocket implementation for nodejs
const WebSocket = require("ws");
// niconizer server
const ws = new WebSocket("ws://localhost:25252/");
// any html content
ws.send("<b>Hello, world!</b>");
const ws = new WebSocket("ws://localhost:25252/");
ws.send("<b>Hello, world!</b>");
wscat -c ws://localhost:25252 -x "$(jq -r '.name' package.json)"
Lint, Format, Build
$ npm run build
Build, Run
$ npm start
Package
$ npm run package
FAQs
A desktop application that displays plain text, images, or any other HTML content on the screen, like nicovideo or bilibili.
The npm package niconizer receives a total of 15 weekly downloads. As such, niconizer popularity was classified as not popular.
We found that niconizer demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.