
Research
/Security News
10 npm Typosquatted Packages Deploy Multi-Stage Credential Harvester
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.
dsmtpd is a small tool to help the developer without an smtp server
::
$ dsmtpd -p 1025 -i 127.0.0.1
2013-01-13 14:00:07,346 INFO: Starting SMTP server at 127.0.0.1:1025
For the installation, we recommend to use a virtualenv, it's the easy way if you want to discover this package::
virtualenv ~/.envs/dsmtpd
source ~/.envs/dsmtpd/bin/activate
pip install dsmtpd
Execute dsmtpd with the --help flag and you will get the usage of this command::
dsmtpd --help
There are three options:
Here is a small example::
dsmtpd
swaks --from stephane@wirtel.be --to foo@bar.com --server localhost --port 1025
dsmtpd uses specific exit codes to indicate the result of its execution.
+------+---------------------------+--------------------------------------------+
| Code | Meaning | Example |
+======+===========================+============================================+
| 0 | Success | Normal shutdown (e.g. user pressed |
| | | Ctrl+C) or clean termination. |
+------+---------------------------+--------------------------------------------+
| 2 | Invalid Maildir directory | The given path exists but does not contain |
| | | the required subfolders: tmp, new, |
| | | and cur. |
+------+---------------------------+--------------------------------------------+
git clone git://github.com/matrixise/dsmtpd.git
Copyright 2013 (c) by Stephane Wirtel
Here you can see the full list of changes between each dsmtpd release.
Released on September 13th 2025.
Release on May 20th 2025.
Release on May 26th 2021.
Release on January 21st 2013.
Release on January 14th 2013.
FAQs
Simple SMTP Server for debugging
We found that dsmtpd demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer.

Product
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.

Security News
Open source dashboard CNAPulse tracks CVE Numbering Authorities’ publishing activity, highlighting trends and transparency across the CVE ecosystem.