
Research
5 Malicious Chrome Extensions Enable Session Hijacking in Enterprise HR and ERP Systems
Five coordinated Chrome extensions enable session hijacking and block security controls across enterprise HR and ERP platforms.
A handy wrapper for reading/writing [secure containers](https://github.com/ExodusMovement/secure-container). Caches the file's `blobKey` & `metadata` to avoid expensive scrypt operations.
A handy wrapper for reading/writing secure containers. Caches the file's blobKey & metadata to avoid expensive scrypt operations.
import createSecoRW from 'seco-rw'
const somefile = createSecoRW('somefile.seco', 'opensesame', {
appName: 'Exodus',
appVersion: '1.0.0'
})
await somefile.write('Hello World!')
await somefile.read().toString('utf8')
// -> Hello World!
createSecoRW(file, passphrase, header)file (String) Path to the secure-containerpassphrase (String | Buffer) Passphrase for the secure-containerheader (Object) Data to write to the secure-container header
appName (String) Name of your appappVersion (String) Your app's version numberwrite(data)data (String | Buffer) Data to write to the fileReturns a Promise that resolves when the file has been written.
read()Returns a Promise, resolving to a Buffer of the file data.
destroy()Destroys the instance and zero-fills the internal cache buffer. Future calls to read() or write() will error out.
If you are using a Buffer passphrase, you may also want to call .fill(0) to zero-fill that too.
MIT
FAQs
A handy wrapper for reading/writing [secure containers](https://github.com/ExodusMovement/secure-container). Caches the file's `blobKey` & `metadata` to avoid expensive scrypt operations.
We found that seco-rw demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Five coordinated Chrome extensions enable session hijacking and block security controls across enterprise HR and ERP platforms.

Research
Node.js patched a crash bug where AsyncLocalStorage could cause stack overflows to bypass error handlers and terminate production servers.

Research
/Security News
A malicious Chrome extension steals newly created MEXC API keys, exfiltrates them to Telegram, and enables full account takeover with trading and withdrawal rights.