Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Soft integration with Cartasì virtual POS X-pay payment system
npm install xpay-js
or clone:
https://github.com/auridevil/xpay-js.git
The module can be directly configured or globaly configured.
Direct configuration:
var xpay = require('xpay-js')({
XPAY_KEY: '123456789012345678901',
XPAY_ALIAS: '7654321',
XPAY_RETURN_URL_OK: 'http:/myserver/okrul',
XPAY_RETURN_URL_KO: 'http:/myserver/korul',
});
For the global configuration you must set the variables:
XPAY_KEY: the key given by cartasi
XPAY_ALIAS: the app alias given by cartasi
XPAY_RETURN_URL_OK: your url to be called on ok
XPAY_RETURN_URL_KO: your url to be called on back
XPAY_SERVLET_URL: the xpay servelt url, default is pre-production enviroment
and require simpler:
var xpay = require('xpay-js')();
The init phase return a function, just invoke the function
var macCode;
var xpayLink = xpay(transactionCode, transactionQuantity, mac);
using the transactionCode you have generated and taking care of using the quantity without decimals dot (e.g. 10€ = 1000). The mac is the generated code to be used in the url.
Feel free to add any improvements and open a pull request.
For more infos about xpay watch http://www.cartasi.it/gtwpages/common/?id=OiRGdkfJWU
Made with love by Aureliano Bergese
Cheers by digitalx. http://digitalx.it/
FAQs
Soft integration with X-pay payment system
The npm package xpay-js receives a total of 2 weekly downloads. As such, xpay-js popularity was classified as not popular.
We found that xpay-js demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.