
Research
lightning PyPI Package Compromised in Supply Chain Attack
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.
smartystreets-javascript-sdk-utils
Advanced tools
Utils library to use with the Smarty Javascript SDK
The Smarty JavaScript SDK Utils provide an additional level of analysis for US Street lookups validated through the Smarty JavaScript SDK. This package consists of the following utilities for Smarty API response analysis.
isValid()Determines if the lookup is considered mail deliverable by the USPS. Returns <Boolean>.
lookup: (<Object>) a validated US Street LookupisInvalid()Determines if the lookup is not considered mail deliverable by the USPS. Returns <Boolean>.
lookup: (<Object>) a validated US Street LookupisAmbiguous()Determines if the lookup returned multiple possible match candidates. Returns <Boolean>.
lookup: (<Object>) a validated US Street LookupisMissingSecondary()Determines if the lookup requires a secondary address. Returns <Boolean>.
lookup: (<Object>) a validated US Street LookupThis example is modified from the US Street API code example.
const SmartySDK = require("smartystreets-javascript-sdk");
const SmartyCore = SmartySDK.core;
const Lookup = SmartySDK.usStreet.Lookup;
const utils = require("smartystreets-javascript-sdk-utils");
let authId = process.env.SMARTY_AUTH_ID;
let authToken = process.env.SMARTY_AUTH_TOKEN;
let clientBuilder = new SmartyCore.ClientBuilder(new SmartyCore.StaticCredentials(authId, authToken));
let client = clientBuilder.buildUsStreetApiClient();
let lookup1 = new Lookup();
lookup1.street = "1600 Pennsylvania Ave NW";
lookup1.city = "Washington";
lookup1.state = "DC";
client.send(lookup1)
.then(handleSuccess)
.catch(handleError);
function handleSuccess(response) {
response.lookups.map(lookup => console.log(lookup.result));
// Is lookup1 valid?
console.log(utils.isValid(response.lookups[0]));
// Is lookup1 invalid?
console.log(utils.isInvalid(response.lookups[0]));
// Is lookup1 ambiguous?
console.log(utils.isAmbiguous(response.lookups[0]));
// Is lookup1 missing a secondary address?
console.log(utils.isMissingSecondary(response.lookups[0]));
}
function handleError(response) {
console.log(response);
}
FAQs
Utils library to use with the Smarty Javascript SDK
The npm package smartystreets-javascript-sdk-utils receives a total of 14,175 weekly downloads. As such, smartystreets-javascript-sdk-utils popularity was classified as popular.
We found that smartystreets-javascript-sdk-utils demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 9 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.