Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
torrent-properties
Advanced tools
this is a package that focuses only on BEP 46. I want webtorrent to have BEP 46 capability but it seems like things has to be changed up under the hood for that which can take time. my thought is that maybe it can be possible to have a total separate package that manages the BEP 46 stuff. this way webtorrent can stay as it is and still gain BEP 46 capability. another good thing is other projects would be able to use this package as well.
https://github.com/RangerMauve/mutable-webtorrent <--- this was made by @rangermauve, it was a great intro and start for me. what i did is take things from this package, changed a few things and added some things as well.
for this package to work, you would just need to pass in an instance of webtorrent dht/bittorent-dht.
reference/guide/inspiration https://github.com/lmatteis/dmt/ https://github.com/webtorrent/webtorrent https://github.com/RangerMauve/mutable-webtorrent
FAQs
BEP 46
The npm package torrent-properties receives a total of 0 weekly downloads. As such, torrent-properties popularity was classified as not popular.
We found that torrent-properties demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.