Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Security News
Douglas Coburn
September 13, 2024
We’re excited to release first version of Socket’s Python Software Development Kit (SDK), now available on PyPI. Our SDK simplifies integrating Socket's security features into your Python applications by providing a user-friendly wrapper around the Socket REST API.
We designed this SDK to make it easier for our customers who user Python to integrate Socket into their workflows. It makes it possible for developers to easily retrieve detailed information on npm package issues, scores, dependencies, organization settings, and more.
Installing the Socket Python SDK is as simple as running:
pip install socket-sdk-python
Developers can then easily integrate the SDK into their projects, allowing them to streamline monitoring and managing package dependencies, retrieving security scores, viewing reports, and tracking issues. Detailed instructions for setting up and using the SDK can be found in the project description on PyPI, including all the available parameters and functions.
Check out our product changelog for all the information on the latest fixes and improvements. Moving forward, all updates will be published to the SDK’s package on PyPI. Feel free to get in touch if you have any feedback or suggestions. We would love to hear from you, as your input helps us continuously improve and tailor the SDK to better meet your security needs.
Subscribe to our newsletter
Get notified when we publish new security blog posts!
Try it now
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.