
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
tasit-contracts
Advanced tools
This package contains the smart contracts (and tests, etc.) from a few of the most popular dapps.
tasit-contracts
This package contains the smart contracts (and tests, etc.) from a few of the most popular dapps.
tasit-contracts
contains a collection of the latest smart contracts from major projects that could be a useful standalone utility even when used outside of the context of the Tasit SDK. Other developers could use this package for testing their own libraries too.
Important note
This child package is still in a coming soon state. If you're checking out this repo for the purposes of considering whether the code is up to your standards, here are some completed portions of the code base to check out:
This functionality all "lives" in tasit-contracts
, a child package of the tasit-sdk
that is also published to npm as a standalone module using lerna.
For context, here is an overview of how this fits in with the rest of the Tasit SDK. But this can be used as a stand-alone, modular package if you prefer!
FAQs
This package contains the smart contracts (and tests, etc.) from a few of the most popular dapps.
We found that tasit-contracts demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.