
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
A Markdown to HTML translator.
[April 15th 2021] This project is a work in progress.
I've recently taken an interest in the syntax and semantics of programming languages, and would like to explore some of the practices involved in writing one. Having said that, I don't want to dive into writing a full featured programming language for various reasons, the primary one being that I don't have any use cases where an existing language could not trivially satisfy my programming needs.
With that in mind I'm going to start smaller with a translator that takes a Markdown source file and outputs HTML. In an ideal world I'd use it as part of another project, but regardless of whether I get that far I'm going to enjoy digging into the challenges involved.
My initial plan is to try and parse Markdown source into an abstract syntax tree of some sort, and then convert that AST into HTML. I'll start with a subset of GitHub flavoured Markdown; I use GitHub's Markdown on a near daily basis, and if I want to use this elsewhere I probably won't have need for a full Markdown feature set.
Rosetta will support the following features. For examples of what these look like in use, visit the GitHub Markdown Guide. I'll mark each item as completed once Rosetta can convert them to its AST representation.
FAQs
Unknown package
We found that rosetta-ruby demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.