
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
This is a non-complete implementation of the Klarna Payment and Klarna Order Management API.
To work properly the library needs credentials for the Klarna API. In development these credentials are read from the environment. In an actual application they are passed in as options to the Klarna::Client
. There must be two variables set when running the tests or the dummy app:
KLARNA_API_KEY
KLARNA_API_SECRET
Both can be obtained from Klarna. There's a third option to set the region; currently tested are us
(default) and uk
.
KLARNA_REGION
The gem comes with a dummy Sinatra app that's used in the specs and can also be used for manual testing against the API. That's because some calls to the API require an authorization_token
which can only be obtained by running frontend code in an iFrame. To run the app, simply execute bin/app
.
The tests can be executed via rake
.
FAQs
Unknown package
We found that swiss-klarna_proxy demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.