
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Stealing this from https://bitbucket.org/mailchimp/mandrill-api-ruby/ as of version 1.0.52, for multiple reasons.
module API
class WhateverController
end
end
Was making ::Mandrill::API or Mandrill::API or whatever, point to the API module, then break. Short version, didnt have ton of time to dig into it, but when I cloned source of mandrill gem off bitbucket I wasn't suprised it was breaking.
So I broke everything into separate files, added some scope resolution operators for safety and speed, and thats the extent of it so far.
I may end up refactoring to make it more resourceful, which is why I elected to release it under a separate gem name, that and the majority of devs will appreciate it being on github, and being able to dig through the source on GH, and it works for now.
require 'mandrill'
or using bundler:
gem 'mandrill-rb'
FAQs
Unknown package
We found that mandrill-rb demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.