
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
tasit-link-wallet
Advanced tools
Library for onboarding a user by linking a dapp with a wallet of their choosing.
tasit-link-wallet
This package helps with onboarding a user by linking a dapp with a wallet of their choosing. This can be done either using ERC20 and ERC721 approve functions or using WalletConnect.
Important note
This onboarding-related child package is still in a coming soon state. If you're checking out this repo for the purposes of considering whether the code is up to your standards, here are some completed portions of the code base to check out:
This functionality all "lives" in tasit-link-wallet
, a child package of the tasit-sdk
that is also published to npm as a standalone module using lerna.
For context, here is an overview of how this fits in with the rest of the Tasit SDK in the onboarding section. But this can be used as a stand-alone, modular package if you prefer!
FAQs
Library for onboarding a user by linking a dapp with a wallet of their choosing.
We found that tasit-link-wallet demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.