Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Analizaruptor is a tool that looks for break
, require
, and provides
commands (and does a teensy bit of code analyzing - it will detect VERY basic
class and module declarations) to make your RubyMotion Rakefile
and
debugger_cmds
files short and consistent.
CAUTION: It overwrites the debugger_cmds
file!
To use, include this gem (gem 'analizaruptor'
), and add app.analyze
to your
Rakefile
, after you have added your libraries and whatnot. It looks at
app.files
and scans those files, so I mean it when I say "after you have added
your libraries and whatnot". In your source code you can add Analizaruptor
commands
# @provides Foo
# @requires Bar
# older syntax:
#--> provides Foo
#--> requires Bar
def scary_method
#-----> break
doing
interesting
stuff
end
And those will be translated into directives for app.files_dependencies
and
debugger_cmds
.
Run rake
or rake debug=1
, and off you go!
The syntax for a command is:
^#[ \t]*@(provides|requires)
or
^#--+> *(break|require|provides)( *(\w+|[0-9]+))?$
If a line number is given to the break
command, a breakpoint will be added at
that line, otherwise it will be added to the line below break
. It's better to
insert the #--> break
where you NEED it, rather than hardcode line numbers.
Line numbers are not constant.
FAQs
Unknown package
We found that analizaruptor demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.