Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
A Python library to parse Instant Readout advertisement data from Victron devices.
Disclaimer: This software is not an officially supported interface by Victron and is provided entirely "as-is"
If you'd like to support development for additional devices, consider creating a pull request with sample advertisement data.
pip install victron_ble
To be able to decrypt the contents of the advertisement, you'll need to first fetch the per-device encryption key from the official Victron application. The method to do this will vary per platform, instructions below:
You can follow the above instruction to get the keys but you will need to pair with your headless system (using bluetoothctl
for ex) to continue the proccess.
MacOS's bleak backend uses a bluetooth UUID address instead of the more traditional MAC address to identify bluetooth devices. This UUID address is often unique to the device scanned and the device being scanned such that it cannot be used to connect to the same device from another computer.
If you are going to use victron-ble
on the same Mac computer as you have the Victron app on, follow the instructions below to retrieve the address UUID and advertisement key:
sqlite3
via Homebrew)❯ sqlite3 ~/Library/Containers/com.victronenergy.victronconnect.mac/Data/Library/Application\ Support/Victron\ Energy/Victron\ Connect/d25b6546b47ebb21a04ff86a2c4fbb76.sqlite 'select address,advertisementKey from advertisementKeys inner join macAddresses on advertisementKeys.macAddress == macAddresses.macAddress'
{763aeff5-1334-e64a-ab30-a0f478s20fe1}|0df4d0395b7d1a876c0c33ecb9e70dcd
❯
Here we're using OSX as an example. If you're using another system, replace the UUID with the real MAC address. The project ships with a standalone CLI that can be used to print device data to the console.
# Will show all discovered Victron devices with Instant Readout enabled, their names, and IDs
$ > victron-ble discover
763aeff5-1334-e64a-ab30-a0f478s20fe1: SmartShunt HT4531A246S
...
# Dump data for a particular device (replace the ID and key with your own)
$ > victron-ble read "763aeff5-1334-e64a-ab30-a0f478s20fe1@0df4d0395b7d1a876c0c33ecb9e70dcd"
INFO:victron_ble.scanner:Reading data for ['763aeff5-1334-e64a-ab30-a0f478s20fe1']
{
"name": "SmartShunt HT4531A246S",
"address": "763AEFF5-1334-E64A-AB30-A0F478S20FE1",
"rssi": -79,
"payload": {
"aux_mode": "temperature",
"consumed_ah": 0.0,
"current": 0.0,
"high_starter_battery_voltage_alarm": false,
"high_temperature_alarm": false,
"high_voltage_alarm": false,
"low_soc_alarm": false,
"low_starter_battery_voltage_alarm": false,
"low_temperature_alarm": false,
"low_voltage_alarm": false,
"midpoint_deviation_alarm": false,
"remaining_mins": 65535,
"soc": 100.0,
"temperature": 382.2,
"voltage": 12.87
}
}
...
# Dump data for debugging and supporting new devices (replace the ID)
$ > victron-ble dump "763aeff5-1334-e64a-ab30-a0f478s20fe1"
Dumping advertisements from 763aeff5-1334-e64a-ab30-a0f478s20fe1
1671843194.0534039 : 100289a302413bafd03bb245e131ae926267f6fd0b59e0
1671843194.682535 : 100289a302423baf58a1546e5262dcdf0ef642f353ed65
1671843197.676384 : 100289a302453baf804707549cffb2ab970c981ae897b6
...
To consume this project as a library, you can import the particular parser for your device:
from victron_ble.devices import detect_device_type
data = <ble advertisement data>
parser = detect_device_type(data)
parsed_data = parser(<key>).parse(<ble advertisement data>)
Victron has published documentation for the instant read-out protocol here.
If you'd like to help support a new device, collect the following and create a new Github issue:
victron-ble discover
to find the ID of the device you'd like to supportvictron-ble dump <ID>
for a few minutes while collecting corresponding screenshots from the official apps instant readout to identify the current valuesFor pull requests:
Read the CONTRIBUTING.md file.
Special thanks to https://github.com/rochacbruno/python-project-template for the project template
FAQs
Python API to read Victron Instant Readout advertisements
We found that victron-ble demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.