Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Slow Web is a way to limit the number of requests to a domain within a certain period of time.
For example, the GitHub API only allows for 60 requests per minute. Slow Web can monitor the number of calls to that domain and will sleep on the next request that is over the limit.
Slow Web follows the rules of Semantic Versioning.
To install Slow Web, simply install the gem:
$ [sudo] gem install slowweb
And specify the domain to limit.
require 'slowweb'
SlowWeb.limit('github.com', 10, 60)
This restricts the github.com
domain to only allowing 10
requests every
60
seconds (or one minute).
If you'd like to contribute to SlowWeb, start by forking the repository on GitHub:
http://github.com/benbjohnson/slowweb
Then follow these steps to send your changes:
FAQs
Unknown package
We found that slowweb demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.