
Research
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.
This is a sub-package of web3.js.
web3-eth contains modules to interact with the Ethereum blockchain and smart contracts.
You can install the package either using NPM or using Yarn
npm install web3-eth
yarn add web3-eth
| Script | Description |
|---|---|
| clean | Uses rimraf to remove dist/ |
| build | Uses tsc to build package and dependent packages |
| lint | Uses eslint to lint package |
| lint:fix | Uses eslint to check and fix any warnings |
| format | Uses prettier to format the code |
| test | Uses jest to run unit tests |
| test:integration | Uses jest to run tests under /test/integration |
| test:unit | Uses jest to run tests under /test/unit |
The ethers.js library is a complete and compact library for interacting with the Ethereum blockchain and its ecosystem. It provides similar functionalities to web3-eth, such as connecting to Ethereum nodes, managing accounts, sending transactions, and interacting with smart contracts. Ethers.js is known for its smaller size and better documentation.
Ethjs is a highly modular and lightweight library for interacting with the Ethereum blockchain. It provides similar functionalities to web3-eth, including sending transactions, managing accounts, and interacting with smart contracts. Ethjs is designed to be simple and easy to use, with a focus on modularity.
Truffle-contract is a library for managing and interacting with Ethereum smart contracts. It provides a higher-level abstraction for working with contracts compared to web3-eth. Truffle-contract is part of the Truffle Suite, which includes tools for developing, testing, and deploying smart contracts.
FAQs
Web3 module to interact with the Ethereum blockchain and smart contracts.
The npm package web3-eth receives a total of 411,470 weekly downloads. As such, web3-eth popularity was classified as popular.
We found that web3-eth demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.