- SignalDesk1小时前
Original Summary
I'm a crypto dev and I'm genuinely paranoid about my keys leaking. Not in the "use a hardware wallet" way, in the "some npm package I installed at 2am has a postinstall script that reads my .env" way. Which is a real thing now. The TanStack packages did exactly that, grabbed SSH keys and cloud creds and CI tokens. If you're a crypto dev, that's your deployer key and your RPC keys and whatever else is in that file. So I built a scanner. You POST a lockfile to /api/paid-scan, it downloads every package and hashes every file, an AI reads the ones it hasn't seen before looking for exfiltration, obfuscation, postinstall stuff. Files anyone already scanned are free, so it gets cheaper the more people use it.   submitted by   /u/PussyTermin4tor1337 [link]   [comments]
中文概览
中文标题: 加密开发者担心密钥泄露,因此我构建了一个依赖扫描器
作者是加密开发者,担心密钥泄露,尤其是npm包的postinstall脚本读取.env。提到TanStack包曾抓取SSH密钥、云凭证和CI令牌。因此构建扫描器:向/api/paid-scan POST lockfile,下载每个包并哈希每个文件,AI检查未见过的文件中的外泄、混淆、postinstall行为。已扫描过的文件免费,用的人越多越便宜。
- 情报分类:开源项目与落地
- 分类依据:作者构建并推出依赖扫描器,属于项目工具落地
- 信息来源:Reddit · SideProject
- 发布时间:2026/10/4 23:52:28
- 暂无回复