
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
github.com/Towsif12/dbus-media-http-api
This HTTP API connects to the host's DBus to retrieve current media information. It exposes an endpoint where this information can be accessed, and various methods can be executed.
GET
/get
Returns a list of all available Mris MediaPlayer2 objects.
{
"error": false,
"result": [
{
"service": "org.mpris.MediaPlayer2.APPLICATION",
"mpris:artUrl": "BASE64 DATA",
"mpris:length": 1230,
"mpris:trackid": "TRACK ID",
"playback_status": "Playing",
"position": 1230,
"volume": 1,
"xesam:album": "",
"xesam:artist": [
"ARTIST"
],
"xesam:title": "TITLE"
}
]
}
GET
/{action}/{service}
Triggers a specified action in the provided service.
playpause
play
pause
stop
next
previous
{"error": false, "message": "ACTION executed successfully"}
[!NOTE] If you have
AUTH=true
andAUTH_KEY=KEY
set in your .env file, you will need to add anAuthorization
header with the authentication key to your requests.
To run this HTTP API, you need a Linux machine with DBus installed. This project integrates with the DBus Mris Media Player for media player interaction. You will also need to compile this project.
To compile and run this project, follow these commands:
git clone https://github.com/Towsif12/dbus-media-http-api.git
cd dbus-media-http-api
go build -o dbus-media-api ./src
chmod +x dbus-media-api
./dbus-media-api
Optionally, you can use a .env
file to configure the port, authentication, and authentication key:
PORT=10004
AUTH=true
AUTH_KEY=key123
The development process is similar to the usage instructions. Start by cloning the repository, and then you can modify the code in the src/
directory.
To run the project during development, use the following command:
go run ./src
Feel free to submit a Pull Request (PR) or post an issue if you encounter any bugs or errors.
These links were helpful resources throughout the development of this project:
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.