Research
Security News
Threat Actor Exposes Playbook for Exploiting npm to Build Blockchain-Powered Botnets
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
IPFS Peer ID implementation in JavaScript.
Generate, import, and export PeerIDs, for use with IPFS.
A Peer ID is the SHA-256 multihash of a public key.
The public key is a base64 encoded string of a protobuf containing an RSA DER buffer. This uses a node buffer to pass the base64 encoded public key protobuf to the multihash for ID generation.
const PeerId = require('peer-id')
PeerId.create({ bits: 1024, keyType: 'rsa' }, (err, id) => {
if (err) { throw err }
console.log(JSON.stringify(id.toJSON(), null, 2))
})
{
"id": "Qma9T5YraSnpRDZqRR4krcSJabThc8nwZuJV3LercPHufi",
"privKey": "CAAS4AQwggJcAgEAAoGBAMBgbIqyOL26oV3nGPBYrdpbv..",
"pubKey": "CAASogEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMBgbIqyOL26oV3nGPBYrdpbvzCY..."
}
> npm i peer-id
const PeerId = require('peer-id')
The code published to npm that gets loaded on require is in fact a ES5 transpiled version with the right shims added. This means that you can require it and use with your favourite bundler without having to adjust asset management process.
const PeerId = require('peer-id')
<script>
TagLoading this module through a script tag will make the PeerId
obj available in
the global namespace.
<script src="https://unpkg.com/peer-id/dist/index.min.js"></script>
<!-- OR -->
<script src="https://unpkg.com/peer-id/dist/index.js"></script>
const PeerId = require('peer-id')
new PeerId(id[, privKey, pubKey])
id: Buffer
- The multihash of the publick key as Buffer
privKey: RsaPrivateKey
- The private keypubKey: RsaPublicKey
- The public keyThe key format is detailed in libp2p-crypto.
create([opts], callback)
Generates a new Peer ID, complete with public/private keypair.
opts: Object
: Default: {bits: 2048, keyType: 'rsa'}
callback: Function
Calls back callback
with err, id
.
createFromHexString(str)
Creates a Peer ID from hex string representing the key's multihash.
createFromBytes(buf)
Creates a Peer ID from a buffer representing the key's multihash.
createFromB58String(str)
Creates a Peer ID from a Base58 string representing the key's multihash.
createFromPubKey(pubKey)
publicKey: Buffer
Creates a Peer ID from a buffer containing a public key.
createFromPrivKey(privKey)
privKey: Buffer
Creates a Peer ID from a buffer containing a private key.
createFromJSON(obj)
obj.id: String
- The multihash encoded in base58
obj.pubKey: String
- The public key in protobuf format, encoded in base64
obj.privKey: String
- The private key in protobuf format, encoded in base64
toHexString()
Returns the Peer ID's id
as a hex string.
1220d6243998f2fc56343ad7ed0342ab7886a4eb18d736f1b67d44b37fcc81e0f39f
toBytes()
Returns the Peer ID's id
as a buffer.
<Buffer 12 20 d6 24 39 98 f2 fc 56 34 3a d7 ed 03 42 ab 78 86 a4 eb 18 d7 36 f1 b6 7d 44 b3 7f cc 81 e0 f3 9f>
toB58String()
Returns the Peer ID's id
as a base58 string.
QmckZzdVd72h9QUFuJJpQqhsZqGLwjhh81qSvZ9BhB2FQi
toJSON()
Returns an obj
of the form
obj.id: String
- The multihash encoded in base58
obj.pubKey: String
- The public key in protobuf format, encoded in 'base64'obj.privKey: String
- The private key in protobuf format, encoded in 'base 64'toPrint()
Returns the Peer ID as a printable string without the Qm
prefix.
Example: <peer.ID xxxxxx>
isEqual(id)
id
can be a PeerId or a Buffer containing the idMIT
FAQs
IPFS Peer Id implementation in Node.js
The npm package peer-id receives a total of 14,490 weekly downloads. As such, peer-id popularity was classified as popular.
We found that peer-id demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
Security News
NVD’s backlog surpasses 20,000 CVEs as analysis slows and NIST announces new system updates to address ongoing delays.
Security News
Research
A malicious npm package disguised as a WhatsApp client is exploiting authentication flows with a remote kill switch to exfiltrate data and destroy files.