
Research
/Security News
Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader
North Korean threat actors deploy 67 malicious npm packages using the newly discovered XORIndex malware loader.
aqwari.net/cmd/gogive
gogive is a tool that establishes an arbitrary mapping between
a list of import paths and their source control repositories for use
with the go get
tool. This allows you to, for example, construct
meaningful import paths under your own site name, such as
import "example.org/net/lldp"
While still taking advantage of third-party code hosting sites like github, which offer a lot in terms of scalability and collabaration tools (issues, etc).
To run gogive
, create a configuration file with lines of the form
prefix vcs repo
Where prefix
is the import path prefix, vcs
is the version control tool,
and repo
is the url of the actual source repository. Then run gogive
:
$ gogive /path/to/gogive-config-file
For use as a service, run it under a supervisor such as Upstart, daemontools, supervisord, or systemd.
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
North Korean threat actors deploy 67 malicious npm packages using the newly discovered XORIndex malware loader.
Security News
Meet Socket at Black Hat & DEF CON 2025 for 1:1s, insider security talks at Allegiant Stadium, and a private dinner with top minds in software supply chain security.
Security News
CAI is a new open source AI framework that automates penetration testing tasks like scanning and exploitation up to 3,600× faster than humans.