
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
[](https://gitter.im/ags131/node-ld?utm_source=badge&utm_medium=badge&utm_campaign=pr-badge&utm_content=badge)
NOTE: This does not currently work for the Xbox version of the toypad. It will connect but no responses will be received. If someone manages to get it working, please let me know so I can make this more compatible.
Node.js 4.1 or newer. https://nodejs.org Tested and developed on node.js 4.1+
I also have a repo available for PC and Arm
wget -O - http://repo.ags131.com/install.sh | sudo bash -
sudo apt-get update
sudo apt-get install nodejs
libusb-1.0
git clone git@github.com:ags131/node-ld
cd node-ld
npm install
Install node-4.1.2 (Latest version that works with node-usb) 32Bit or 64Bit
Use Zadig to (In tools folder) to install the USB driver
LEGO READER V2.10
See demo.js and toypadDemo.js in the samples folder for example usage
FAQs
[](https://gitter.im/ags131/node-ld?utm_source=badge&utm_medium=badge&utm_campaign=pr-badge&utm_content=badge)
The npm package node-ld receives a total of 1 weekly downloads. As such, node-ld popularity was classified as not popular.
We found that node-ld demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.