
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
voxels-scripting-server
Advanced tools
A package to allow people to create their own persistent scripting server. This module exports two objects:
makeVSS()
; This function returns a promise containing the WebSocketServer when it has successfully started.expressApp
which is the express app
object. See the express npm module documentation.Run npm i
Import makeVSS
and enter a few lines of code:
Using import
import {makeVSS} from 'voxels-scripting-server'
makeVSS(670).then((wss) => {
if (wss) {
console.log("Websocket started");
} else {
console.error("Websocket did not start");
}
});
Using require:
const vss =require("voxels-scripting-server");
vss.default.makeVSS(670).then((wss) => {
if (wss) {
console.log("Websocket started");
} else {
console.error("Websocket did not start");
}
});
There is a demo on repl.it: https://replit.com/@Benjythebee/testCryptovoxelsserver#index.js
In the examples above, replace 670
with the parcel id or space id you want to create a server for.
Once your server setup, go to your parcel page on Voxels.com and set Hosted script
to true;
Then set the host address to wss://[The Address of server]/
, Hit save.
Clone the repo
npm run test:server
will run a quick test server in client/server
using the source code.
npm run test:client
will run a quick test client in client/client_test.ts
.
Create a branch and do your changes
Make sure your code is formatted using npm run format
Also make sure your code builds using npm run build
Create a Pull request at https://github.com/cryptovoxels/Voxels-Scripting-Server .
Any ideas are welcomed
FAQs
A basic server to run Voxels.com scripts
We found that voxels-scripting-server demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.