
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
syscoinjs-lib
Advanced tools
A transaction creation library interfacing with coin selection for Syscoin.
A javascript Syscoin library for node.js and browsers.
Released under the terms of the MIT LICENSE.
If you are thinking of using the master branch of this library in production, stop. Master is not stable; it is our development branch, and only tagged releases may be classified as stable.
Don't trust. Verify.
We recommend every user of this library and the syscoin ecosystem audit and verify any underlying code for its validity and suitability, including reviewing any and all of your project's dependencies.
Mistakes and bugs happen, but with your help in resolving and reporting issues, together we can produce open source software that is:
Buffer's throughout, andPresently, we do not have any formal documentation other than our examples, please ask for help if our examples aren't enough to guide you.
npm install syscoinjs-lib
Typically we support the Node Maintenance LTS version. If in doubt, see the .travis.yml for what versions are used by our continuous integration tests.
WARNING: We presently don't provide any tooling to verify that the release on npm matches GitHub. As such, you should verify anything downloaded by npm against your own verified copy.
Crypto is hard.
When working with private keys, the random number generator is fundamentally one of the most important parts of any software you write.
For random number generation, we default to the randombytes module, which uses window.crypto.getRandomValues in the browser, or Node js' crypto.randomBytes, depending on your build system.
Although this default is ~OK, there is no simple way to detect if the underlying RNG provided is good enough, or if it is catastrophically bad.
You should always verify this yourself to your own standards.
This library uses bitcoinjs-lib with the ECC backend @bitcoinerlab/secp256k1, which uses RFC6979 to help prevent k re-use and exploitation.
Unfortunately, this isn't a silver bullet.
Often, Javascript itself is working against us by bypassing these counter-measures.
Problems in Buffer (UInt8Array), for example, can trivially result in catastrophic fund loss without any warning.
It can do this through undermining your random number generation, accidentally producing a duplicate k value, sending Bitcoin to a malformed output script, or any of a million different ways.
Running tests in your target environment is important and a recommended step to verify continuously.
Finally, adhere to best practice. We are not an authorative source of best practice, but, at the very least:
Math.random - in any way - don't.The recommended method of using syscoinjs-lib in your browser is through Browserify.
If you're familiar with how to use browserify, ignore this and carry on, otherwise, it is recommended to read the tutorial at https://browserify.org/.
NOTE: We use Node Maintenance LTS features, if you need strict ES5, use --transform babelify in conjunction with your browserify step (using an es2015 preset).
WARNING: iOS devices have problems, use atleast buffer@5.0.5 or greater, and enforce the test suites (for Buffer, and any other dependency) pass before use.
These are the functions available on SyscoinJS library with links to the code which has commenting on the function itself:
These are some supporting functions used to support the library like working with backend providers (Blockbook) and sanitizing data from the providers:
These are the HDSigner exported functions, HDSigner is used to manage creating addresses and sign transactions internally using your XPUB (HD wallets). BIP44/BIP84 are supported. P2WPKH, P2WSH, P2PKH, P2SH:
If you are looking to generate addresses, use WIFs or anything specific around crafting or doing blockchainy things not related to transaction creation, you may use bitcoinjs-lib and use the Syscoin network parameters (see utils.js for the exported syscoinNetworks parameters).
The below examples are implemented as example tests, they should be very easy to understand. Otherwise, pull requests are appreciated.
If you have a use case that you feel could be listed here, please ask for it!
The createTransaction method now supports the subtractFeeFrom option in outputs. This allows you to subtract the transaction fee from specific outputs instead of requiring additional inputs for fees.
const outputs = [
{
address: 'sys1q6f2053q2fnlqpxrwrrqpkhnutwemu984p4vjzm',
value: new BN(100000000), // 1 SYS
subtractFeeFrom: true // Fee will be deducted from this output
}
];
// Fee is automatically subtracted from outputs marked with subtractFeeFrom
const result = await syscoinjs.createTransaction(txOpts, changeAddress, outputs, feeRate);
When using multiple outputs with subtractFeeFrom, the fee is deducted sequentially:
const outputs = [
{
address: 'sys1q6f2053q2fnlqpxrwrrqpkhnutwemu984p4vjzm',
value: new BN(50000000), // 0.5 SYS
subtractFeeFrom: true // Fee deducted from here first
},
{
address: 'sys1q9vza2e8x573nczrlzms0wvx3gsqjx7vavgkx0l',
value: new BN(50000000), // 0.5 SYS
subtractFeeFrom: true // Only used if first output can't cover full fee
}
];
All transaction creation methods now provide better error handling with structured error objects containing:
Example error handling:
try {
const result = await syscoinjs.createTransaction(txOpts, changeAddress, outputs, feeRate);
console.log('Transaction created successfully');
console.log('Fee spent:', result.fee);
} catch (error) {
console.error('Transaction creation failed:', error.message);
// Access structured error data
if (error.code === 'INSUFFICIENT_FUNDS' && error.shortfall) {
console.error('Short by:', error.shortfall, 'satoshis');
}
if (error.remainingFee) {
console.error('Remaining fee that could not be deducted:', error.remainingFee);
}
}
All transaction creation methods now return an object containing:
Example:
const result = await syscoinjs.createTransaction(txOpts, changeAddress, outputs, feeRate);
console.log('PSBT:', result.psbt);
console.log('Transaction fee:', result.fee, 'satoshis');
See CONTRIBUTING.md.
npm test
npm run-script coverage
This library consumes syscointx-js for raw transaction serializing and deserializing, that library consumes coinselectsyscoin for the UTXO selection and transaction funding algorithms. Other supporting libraries are:
FAQs
A transaction creation library interfacing with coin selection for Syscoin.
The npm package syscoinjs-lib receives a total of 77 weekly downloads. As such, syscoinjs-lib popularity was classified as not popular.
We found that syscoinjs-lib demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.