
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
swarm-peer-server
Advanced tools
A network swarm for creating secure P2P connections over Bittorrent DHT, DNS, and mDNS.
A network swarm for creating secure P2P connections over Bittorrent DHT, DNS, and mDNS.
Uses discovery-swarm to find and connect peers. Connections use asymmetric encryption and Elliptic-curve Diffie-Hellman to establish a secure communication channel. Clients must know the public key of a peer ahead of time to initiate the connection.
Depends on native modules libsodium (via sodium-native) and libutp (via utp-native).
npm install swarm-peer-server
var swarm = require('swarm-peer-server')
swarm.listen({
publicKey: Buffer.from('...'),
secretKey: Buffer.from('...')
}, (socket, peerKey, info) => {
console.log('New authenticated connection')
socket.once('data', data => {
console.log('Received:', data.toString())
socket.destroy()
})
})
var swarm = require('swarm-peer-server')
var { socket } = await swarm.connect({
publicKey: Buffer.from('...'),
secretKey: Buffer.from('...'),
hostPublicKey: Buffer.from('...')
})
console.log('Established connection')
const data = Buffer.from('hello world')
socket.write(data)
examples/echo.js # CLI echo server
var sw = swarm.listen(opts)
Create a new swarm server. Options include:
{
publicKey: crypto.randomBytes(32), // server public key
secretKey: crypto.randomBytes(64), // server secret key
convert: false, // convert signatures to authentication encryption [1]
}
[1] https://download.libsodium.org/doc/advanced/ed25519-curve25519.html
For full list of options take a look at discovery-swarm or the TypeScript definitions.
swarm.connect(opts, (socket, peerKey, info) => {})
Create a new swarm server. Options include:
{
hostPublicKey: crypto.randomBytes(32), // host/server public key
publicKey: crypto.randomBytes(32), // client public key
secretKey: crypto.randomBytes(64), // client secret key
convert: false, // convert signatures to authentication encryption
}
MIT
FAQs
A network swarm for creating secure P2P connections over Bittorrent DHT, DNS, and mDNS.
The npm package swarm-peer-server receives a total of 1 weekly downloads. As such, swarm-peer-server popularity was classified as not popular.
We found that swarm-peer-server demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.