Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
This project provides a basic MVC framework on top of the Shoes environment for those of us strange people who have done MVC so long it's extremely difficult to think about applications other ways.
NOTE: this code is highly experimental and an early work in progress. It wouldn't be wise to rely on it right now for anything other than experiments, prototypes and proofs of concept.
The normal way to ensure this gem is installed is to add it to the Shoes.setup block, e.g.
Shoes.setup do
gem 'shoes_mvc'
end
As of version 0.0.0, it's available as a gem from rubygems.org, so this should just work. If you're using the Rails integration, you'll also need to have a version of ActiveRecord installed.
If you're building it manually (because you're hacking on it), then you'll need to install it yourself in the local Shoes gem directory for your user. On MacOS X, you can do it like this:
$ gem build shoes_mvc.gemspec
$ gem install --install-dir $HOME/.shoes/+gem ./*.gem
The following issues are related to getting this gem actually installed and working as expected:
With Policeman, the Encoding class doesn't seem to actually be defined completely. As a result, anything to do with Encoding and ActiveRecord chokes fairly hard. The "solution" is to hack the encoding.rb file in activesupport so that it defines #encoding_supported? as false. Neat, huh?
Hopefully, this will all get fixed with the next release of Shoes. :(
FAQs
Unknown package
We found that shoes_mvc demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.