
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Command line tool to copy the latest OTP received in the connected Android device to the clipboard.
Command line tool to copy the latest OTP received in the connected Android device to the clipboard.
Simply because I don't want to pickup my phone, open the SMS app, remember the OTP, and then enter it.
Now you might say, haven't you heard about https://messages.google.com? Well, that's what is being used in the package. Selenium Chrome driver automates this process.
cpotp can be installed using pip
pip install cpotp
or install it from the source
git clone https://github.com/riteshpanjwani/cpotp.git
cd cpotp
python setup.py install
If you are using any fairly recent Debian Linux-based OS:
sudo apt install xclip
else, you can install it directly from the source:
git clone https://github.com/astrand/xclip.git
./bootstrap
./configure
make
make install
Verify that it installed:
man xclip
Next, you need to set an environment variable called CHROME_USER_DATA_DIR, in Chrome/Edge/Chromium browser new tab
chrome://version
and set this environment variable to path given in "Profile Path" except the "/Default" part. For example:
export CHROME_USER_DATA_DIR=/home/<username>/.config/google-chrome
Selenium will create a Chrome user profile called "cpotp" in this directory.
Note: the following command downloads the following files on the first run:
On the first run, scan the QR code using your Messages app on the phone and pair it. Close any instance of https://messages.google.com and fire up a terminal / command prompt and run:
cpotp-setup
On subsequent runs, you just have to run:
cpotp
For license information, see LICENSE.md.
FAQs
Command line tool to copy the latest OTP received in the connected Android device to the clipboard.
We found that cpotp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.