Research
Security News
Threat Actor Exposes Playbook for Exploiting npm to Build Blockchain-Powered Botnets
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
An SSB utility library for handling and converting SSB URIs
This library provides utilities that recognize SSB URIs according to the spec, and is compatible with ssb-uri (prior work), while adding more support and more utilities.
npm install ssb-uri2
const ssbUri = require("ssb-uri2");
const exampleURI =
"ssb:message/classic/g3hPVPDEO1Aj_uPl0-J2NlhFB2bbFLIHlty-YuqFZ3w=";
ssbUri.isClassicMessageSSBURI(exampleURI);
// true
ssbUri.toMessageSigil(exampleURI);
// '%g3hPVPDEO1Aj/uPl0+J2NlhFB2bbFLIHlty+YuqFZ3w=.sha256'
isSSBURI(uri: string | uri): boolean
isClassicFeedSSBURI(uri: string | null): boolean
isBendyButtV1FeedSSBURI(uri: string | null): boolean
isButtwooV1FeedSSBURI(uri: string | null): boolean
isIndexedV1FeedSSBURI(uri: string | null): boolean
isGabbyGroveV1FeedSSBURI(uri: string | null): boolean
isFeedSSBURI(uri: string | null): boolean
isClassicMessageSSBURI(uri: string | null): boolean
isBendyButtV1MessageSSBURI(uri: string | null): boolean
isGabbyGroveV1MessageSSBURI(uri: string | null): boolean
isButtwooV1MessageSSBURI(uri: string | null): boolean
isIndexedV1MessageSSBURI(uri: string | null): boolean
isMessageSSBURI(uri: string | null): boolean
isClassicBlobSSBURI(uri: string | null): boolean
isAddressSSBURI(uri: string | null): boolean
isEncryptionKeyBox2DMDiffieHellmanSSBURI(uri: string | null): boolean
isIdentityPOBoxSSBURI(uri: string | null): boolean
isIdentityFusionSSBURI(uri: string | null): boolean
isExperimentalSSBURI(uri: string | null): boolean
isExperimentalSSBURIWithAction(action: string): (uri: string) => boolean
getFeedSSBURIRegex() => RegExp
getMessageSSBURIRegex() => RegExp
fromFeedSigil(sigil: string): string
fromMessageSigil(sigil: string): string
fromBlobSigil(sigil: string): string
fromMultiserverAddress(msaddr: string): string
toFeedSigil(uri: string): string | null
toMessageSigil(uri: string): string | null
toBlobSigil(uri: string): string | null
toMultiserverAddress(uri: string): string | null
compose(parts: {type, format, data, extraData}): string
decompose(uri: string): {type, format, data, extraData}
The object {type, format, data}
is such that it matches ssb:${type}/${format}/${data}
, except the data
is always in normal Base64 (i.e. not URI safe).
There is also the case of extraData
for special URIs such as ssb:feed/buttwoo-v1/${data}/${extraData}
.
LGPL-3.0
FAQs
Utilities for recognizing and converting SSB URIs
The npm package ssb-uri2 receives a total of 170 weekly downloads. As such, ssb-uri2 popularity was classified as not popular.
We found that ssb-uri2 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
Security News
NVD’s backlog surpasses 20,000 CVEs as analysis slows and NIST announces new system updates to address ongoing delays.
Security News
Research
A malicious npm package disguised as a WhatsApp client is exploiting authentication flows with a remote kill switch to exfiltrate data and destroy files.