
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
ya-ts-client
Advanced tools
TypeScript generated API clients for various Yagna public APIs. Core library for Golem Network related libraries and SDKs
The ya-ts-client package provides low level API bindings in form of collection TypeScript clients generated from
the Yagna public API OpenApi specifications.
The primary and only purpose of this package is to provide that basic implementation. As a "core" library, it shouldn't need to be added as a dependency to any user code, only to other Golem Network related SDKs or libraries.
If you want to start building solutions using Golem Network, here are more suitable options:
@golem-sdk/golem-js and provides a "task oriented" API for simple distributed computation scenariosnpm install --save ya-ts-client
The library exposes multiple API clients which are auto-generated from the official OpenApi specifications. The documentation of the generated API is hosted on GitHub pages.
Here's just one example of how to use the Payment module's ApiClient to obtain the list of allocations.
import { PaymentApi } from "ya-ts-client";
// Or refer to the whole library:
//import * as YaTsClient from "ya-ts-client";
/**
* Example of usage of the Payment API
*/
const payment = new PaymentApi.Client({
BASE: "http://localhost:7465/payment-api/v1",
HEADERS: {
Authorization: "Bearer your-app-key",
},
});
const allocations = await payment.requestor.getAllocations();
console.log("Allocated funds:", allocations);
FAQs
TypeScript generated API clients for various Yagna public APIs. Core library for Golem Network related libraries and SDKs
The npm package ya-ts-client receives a total of 140 weekly downloads. As such, ya-ts-client popularity was classified as not popular.
We found that ya-ts-client demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.

Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.

Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.