Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
testing tls, included a self signed cert run the client with this env variable `NODE_TLS_REJECT_UNAUTHORIZED=0`
testing tls, included a self signed cert
run the client with this env variable
NODE_TLS_REJECT_UNAUTHORIZED=0
basic usage
const Server = require('smtpjs')
const server = new Server()
// outputs >> [2020-06-22T02:39:08.611Z] [LOG] - Server start on ip: 127.0.0.1 port: 1337
the 1st argument accepts a schema the second any dependencies
const Server = require('smtpjs')
const schema = {}
const dependencies = {
logger: {...} // see `Logger Options`
}
const server = new Server(schema, dependencies)
theres all the smtp commands that fire if defined for example the HELO command
const schema = {
events: {
HELO (ctx) {
// when server receives the `HELO` it runs this code block
this.logger.debug(' - promise')
return new Promise ((resolve, reject) => {
this.logger.debug(' - timeout')
setTimeout(() => {
this.logger.info('wait 1 second')
resolve('done')
},1000)
})
}
// outputs on HELO
// [2020-06-22T03:01:21.523Z] [DEBUG] - - promise
// [2020-06-22T03:01:21.523Z] [DEBUG] - - timeout
// [2020-06-22T03:01:22.528Z] [INFO] - wait 1 second
}
}
not only are the stmp commands but there are 3 additional
on connect
, error
, and done
accepts a Socket object, which is the nodejs Socket with additional field
id
const schema = {
events: {
connect (socket) {
const ip = socket.remoteAddress
const id = socket.id
this.logger.log(`id: ${id} ip: ${ip}`)
},
}
}
accepts error object and the current status of the email
const schema = {
events: {
error (error, mail) {
// log error?
this.logger.log('Error', error)
// still want to see what the mail is
this.logger.log(mail)
},
}
}
220 - SMTP Service ready.
221 - Service closing.
250 - Requested action taken and completed.
251 - The recipient is not local to the server, but the server will accept and forward the message.
252 - The recipient cannot be verified, but the server accepts the message and attempts delivery.
354 - Start message input and end with .. This indicates that the server is ready to accept the message itself (after you have told it who it is from and where you want to to go).
421 - The service is not available and the connection will be closed.
450 - The requested command failed because the user's mailbox was unavailable (for example because it was locked). Try again later.
451 - The command has been aborted due to a server error. Not your fault. Maybe let the admin know.
452 - The command has been aborted because the server has insufficient system storage.
500 - The server could not recognize the command due to a syntax error.
501 - A syntax error was encountered in command arguments.
502 - This command is not implemented.
503 - The server has encountered a bad sequence of commands.
504 - A command parameter is not implemented.
521 - This host never accepts mail; a response by a dummy server.
541 - The message could not be delivered for policy reasons—typically a spam filter. (Only some SMTP servers return this error code.)
550 - The requested command failed because the user's mailbox was unavailable (for example because it was not found, or because the command was rejected for policy reasons).
551 - The recipient is not local to the server. The server then gives a forward address to try.
552 - The action was aborted due to exceeded storage allocation.
553 - The command was aborted because the mailbox name is invalid.
554 - The transaction failed. Blame it on the weather.
555 - The server does not recognize the email address format, and delivery is not possible.
556 - The message would have to be forwarded, but the receiving server will reject it.
FAQs
testing tls, included a self signed cert run the client with this env variable `NODE_TLS_REJECT_UNAUTHORIZED=0`
We found that smtpjs demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.