Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
shapeshift.io api for node.js (unofficial)
ShapeShift is an instant exchange for Litecoin, Bitcoin, Peercoin, Dogecoin, Darkcoin, and other cryptocoins. As a new service, it is the fastest way to trade between these digital currencies. An exchange between coins on ShapeShift takes only a few seconds, and no account is needed.
The benefit of this is that you could have a web site where a payout to a content provider is paid out in a different currency than what the consumer paid with. For example, Joe wants to be paid in Bitcoin, while Sally wants to pay in Litecoin.
Gets the current rate offered by Shapeshift.
var pair = 'btc_ltc';
shapeshift.getRate(pair)
.then(function(data){
var body = data.body;
//{"pair":"btc_ltc","rate":"93.83852691"}
};
Gets the current deposit limit set by Shapeshift.
var pair = 'btc_ltc';
shapeshift.getLimit(pair)
.then(function(data){
var body = data.body;
//{"pair":"btc_ltc","limit":"1.98046131"}
});
btc, ltc, ppc, drk, doge
use an underscore to seperate currencies in a pair (ie: ltc_doge
or doge_ltc
)
License MIT
FAQs
shapeshift.io api for node.js
The npm package shapeshift receives a total of 12 weekly downloads. As such, shapeshift popularity was classified as not popular.
We found that shapeshift demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.