
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Ever installed a package to later find out that you don't have that package's @typings/ installed ? If yes, this is the solution for that.
Package Name is with-types. Install it using your favorite Package Manager.
A local installation is not required if you are using pnpm or npm. As pnpx and npx allow downloading a package and execute it without installation.
With Yarn 2.0, this is achievable using yarn dlx
Choose any of the following commands.
# Optional Step with npx
npm install with-types --save-dev
# Optional Step with pnpx
pnpm add with-types --save-dev
# Optional Step with Yarn 2.0 but required for lesser versions
yarn add with-types --dev
NOTE: If the package is installed locally, you can use a shorthand wt instead of with-types. So, npx with-types become npx wt
To install a package with it's typings
npx with-types install PACKAGE_NAME --save-dev # Supports same flags as npm
or
pnpx with-types install PACKAGE_NAME --save-dev # Supports same flags as pnpm
or
yarn with-types install PACKAGE_NAME --dev # Supports same flags as yarn. It assumes that package is installed locally.
To uninstall a package and it's typings
npx with-types uninstall PACKAGE_NAME
or
pnpx with-types uninstall PACKAGE_NAME
or
yarn with-types uninstall PACKAGE_NAME
FAQs
Install/Uninstall Packages with their types(@types/*)
We found that with-types demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.

Research
A malicious package uses a QR code as steganography in an innovative technique.

Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.