Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
xd-smtp-connection
Advanced tools
SMTP client module. Connect to SMTP servers and send mail with it.
This module is the successor for the client part of the (now deprecated) SMTP module simplesmtp. For matching SMTP server see smtp-server.
Install with npm
npm install smtp-connection
Require in your script
var SMTPConnection = require('smtp-connection');
var connection = new SMTPConnection(options);
Where
options defines connection data
true
) or not (if false
)true
then logs to console. If value is not set or is false
then nothing is loggedsecure
option is true, then socket is upgraded from plaintext to ciphertextSMTPConnection instances are event emitters with the following events
Establish the connection
connection.connect(callback)
Where
After the connect event the connection
has the following properties:
true
then the connection uses a TLS socket, otherwise it is using a cleartext socket. Connection can start out as cleartext but if available (or requireTLS
is set to true) connection upgrade is triedIf the server requires authentication you can login with
connection.login(auth, callback)
Where
auth is the authentication object
pass
and xoauth2
values are set) or an XOAuth2 token generator object.callback is the callback to run once the authentication is finished. Callback has the following arguments
If a XOAuth2 token generator is used as the value for auth.xoauth2
then you do not need to set auth.user
. XOAuth2 generator generates required accessToken itself if it is missing or expired. In this case if the authentication fails, a new token is requeested and the authentication is retried. If it still fails, an error is returned.
XOAuth2 Example
var generator = require('xoauth2').createXOAuth2Generator({
user: '{username}',
clientId: '{Client ID}',
clientSecret: '{Client Secret}',
refreshToken: '{refresh-token}'
});
// listen for token updates
// you probably want to store these to a db
generator.on('token', function(token){
console.log('New token for %s: %s', token.user, token.accessToken);
});
// login
connection.login({
xoauth2: generator
}, callback);
smtp-connection
has experimental support for NTLM authentication. You can try it out like this:
connection.login({
domain: 'windows-domain',
workstation: 'windows-workstation',
user: 'user@somedomain.com',
pass: 'pass'
}, callback);
I do not have access to an actual server that supports NTLM authentication so this feature is untested and should be used carefully.
Once the connection is authenticated (or just after connection is established if authentication is not required), you can send mail with
connection.send(envelope, message, callback)
Where
envelope is the envelope object to use
envelope.from is the sender address
envelope.to is the recipient address or an array of addresses
envelope.size is an optional value of the predicted size of the message in bytes. This value is used if the server supports the SIZE extension (RFC1870)
envelope.use8BitMime if true
then inform the server that this message might contain bytes outside 7bit ascii range
envelope.dsn is the dsn options
message is either a String, Buffer or a Stream. All newlines are converted to \r\n and all dots are escaped automatically, no need to convert anything before.
callback is the callback to run once the sending is finished or failed. Callback has the following arguments
err and error object if sending failed
response
string (if available)info information object about accepted and rejected recipients
Use it for graceful disconnect
connection.quit();
Use it for less graceful disconnect
connection.close();
Use it to reset current session (invokes RSET command)
connection.reset(callback);
MIT
v1.0.0 2014-09-26
once('error')
handler as an error might have been emitted twiceFAQs
Connect to SMTP servers
The npm package xd-smtp-connection receives a total of 3 weekly downloads. As such, xd-smtp-connection popularity was classified as not popular.
We found that xd-smtp-connection demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.