Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
This is a small library that converts currencies using exchange rates from http://exchange-rates.org web site.
gem install currency_switcher
There are two ways of using the library:
From the available list of currencies you can create methods in a format specified below and call them on Fixnums:
'from_currency'to'to_currency'
For example:
require 'currency_switcher'
# Convert 3 US Dollars to British Pounds
3.usd_to_gbp
# Convert 15 Euros to Australian Dollars
15.eur_to_aud
2) Pass currencies as the arguments:
For example:
require 'currency_switcher'
# Convert 3 US Dollars to British Pounds
3.exchange("usd", "gbp")
aed => United Arab Emirates Dirham
amd => Armenian Dram
ang => Netherlands Antillian Guilder
ars => Argentine Peso
aud => Australian Dollar
bbd => Barbados Dollar
bdt => Bangladeshi Taka
bgn => Bulgarian Lev
bhd => Bahraini Dinar
bif => Burundi Franc
bmd => Bermudian Dollar
bnd => Brunei Dollar
bob => Bolivian Boliviano
brl => Brazilian Real
bsd => Bahamian Dollar
bwp => Botswana Pula
byr => Belarusian Ruble
bzd => Belize Dollar
cad => Canadian Dollar
chf => Swiss Franc
clp => Chilean Peso
cny => Chinese Yuan Renminbi
cop => Colombian Peso
crc => Costa Rican Colon
cup => Cuban Peso
cve => Cape Verde Escudo
czk => Czech Koruna
djf => Djibouti Franc
dkk => Danish Krone
dop => Dominican Peso
dzd => Algerian Dinar
eek => Estonian Kroon
egp => Egyptian Pound
etb => Ethiopian Birr
eur => Euro
fjd => Fiji Dollar
gbp => British Pound
ghs => Ghanaian Cedi
gmd => Gambian Dalasi
gtq => Guatemalan Quetzal
hkd => Hong Kong Dollar
hnl => Honduran Lempira
hrk => Croatian Kuna
htg => Haitian Gourde
huf => Hungarian Forint
idr => Indonesian Rupiah
ils => Israeli New Shekel
inr => Indian Rupee
iqd => Iraqi Dinar
irr => Iranian Rial
isk => Iceland Krona
jmd => Jamaican Dollar
jod => Jordanian Dinar
jpy => Japanese Yen
kes => Kenyan Shilling
khr => Cambodian Riel
krw => Korean Won
kwd => Kuwaiti Dinar
kyd => Cayman Islands Dollar
kzt => Kazakhstan Tenge
lak => Lao Kip
lbp => Lebanese Pound
lkr => Sri Lanka Rupee
lsl => Lesotho Loti
ltl => Lithuanian Litas
lvl => Latvian Lats
lyd => Libyan Dinar
mad => Moroccan Dirham
mdl => Moldovan Leu
mmk => Myanmar Kyat
mop => Macau Pataca
mur => Mauritius Rupee
mwk => Malawi Kwacha
mxn => Mexican Peso
myr => Malaysian Ringgit
ngn => Nigerian Naira
nio => Nicaraguan Cordoba Oro
nok => Norwegian Krone
npr => Nepalese Rupee
nzd => New Zealand Dollar
omr => Omani Rial
pab => Panamanian Balboa
pen => Peruvian Nuevo Sol
php => Philippine Peso
pkr => Pakistan Rupee
pln => Polish Zloty
pyg => Paraguay Guarani
qar => Qatari Rial
ron => Romanian Leu
rsd => Serbian Dinar
rub => Russian Ruble
rwf => Rwanda Franc
sar => Saudi Riyal
scr => Seychelles Rupee
sdd => Sudanese Dinar
sek => Swedish Krona
sgd => Singapore Dollar
sos => Somali Shilling
syp => Syrian Pound
szl => Swaziland Lilangeni
thb => Thai Baht
tnd => Tunisian Dinar
try => Turkish Lira
ttd => Trinidad and Tobago Dollar
twd => Taiwan Dollar
tzs => Tanzanian Shilling
uah => Ukraine Hryvnia
ugx => Uganda Shilling
usd => US Dollar
uyu => Uruguay Peso
vef => Venezuelan Bolivar
vnd => Vietnamese Dong
xaf => CFA BEAC Franc
xcd => East Caribbean Dollar
xof => CFA BCEAO Franc
xpf => CFP Franc
zar => South African Rand
zmk => Zambian Kwacha
zwd => Zimbabwe Dollar
FAQs
Unknown package
We found that currency_switcher demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.