
Research
Malicious NuGet Packages Typosquat Nethereum to Exfiltrate Wallet Keys
The Socket Threat Research Team uncovered malicious NuGet packages typosquatting the popular Nethereum project to steal wallet keys.
Contract addresses, chain data, and deployment information for the Sablier Protocol
Contract addresses, chain data, and deployment information for Sablier, the token distribution protocol for Ethereum and EVM-compatible chains.
This package provides:
bun add sablier
# or
npm install sablier
# or
pnpm add sablier
# or
yarn add sablier
Mainnets: Ethereum, Arbitrum, Optimism, Polygon, Base, BSC, Avalanche, and 20+ more.
Testnets: Sepolia, Base Sepolia, Optimism Sepolia, and more.
The addresses are provided in this package, but you can also view the deployment addresses on the Sablier Docs website:
Our chain types extend upon Viem's Chain.
import { chains, sablier } from "sablier";
// Get by name
const mainnet = chains.mainnet;
// Get chain by ID
const arbitrum = sablier.chains.queries.get({ chainId: 42161 });
// Get chain by slug
const polygon = sablier.chains.queries.get({ slug: "polygon" });
// Check if chain supports Sablier UI
if (arbitrum.isSupportedByUI) {
console.log("Arbitrum available on app.sablier.com");
}
import { releases, sablier } from "sablier";
// Get contract by name and chain
const lockup = sablier.contracts.get({
name: "SablierLockup",
release: releases.lockup["v2.0"],
});
import { releases, sablier } from "sablier";
// Get specific releases
const airdropsV1_3 = releases.airdrops["v1.3"];
const lockupV2_0 = releases.lockup["v2.0"];
const flowV1_1 = releases.flow["v1.1"];
// Get all Lockup releases
const allLockups = sablier.releases.getAll({ protocol: "lockup" });
See the types for more information.
interface Release {
protocol: "flow" | "lockup" | "airdrops" | "legacy";
version: "v1.0" | "v1.1" | "v2.0" | ...;
isLatest: boolean;
contractNames: string[];
deployments: Deployment[];
}
The deployment broadcasts (generated with Foundry) are
located under the deployments
directory.
Each deployment is stored as JSON with a structure like this, which is generated by Foundry:
{
"transactions": [...], // Deployment transactions
"receipts": [...], // Transaction receipts
"libraries": [...], // Linked libraries
"returns": { // Deployed contract addresses
"flow": "0x...",
"nftDescriptor": "0x..."
},
"timestamp": 1738015038, // Deployment timestamp
"chain": 1, // Chain ID
"commit": "a0fa33d" // Git commit hash
}
We welcome contributions!
For guidance on how to make PRs, see the CONTRIBUTING guide.
This project is licensed under GPL-3.0-or-later.
FAQs
Contract addresses, chain data, and deployment information for the Sablier Protocol
The npm package sablier receives a total of 463 weekly downloads. As such, sablier popularity was classified as not popular.
We found that sablier demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
The Socket Threat Research Team uncovered malicious NuGet packages typosquatting the popular Nethereum project to steal wallet keys.
Product
A single platform for static analysis, secrets detection, container scanning, and CVE checks—built on trusted open source tools, ready to run out of the box.
Product
Socket is launching experimental protection for the Hugging Face ecosystem, scanning for malware and malicious payload injections inside model files to prevent silent AI supply chain attacks.