Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
github.com/ic-n/flow-control
Flow is an experiment to check if go generics give more room for code obfuscation and a known problem from other languages - toxic senior++ code, only readable by experts with proper context, overcomplicated to be scary for newcomers. The answer is undoubtedly yes; it gives developers a chance to write such sophisticated constructs, so it's terrifing but remail "legal" code. Anyway, I am still determining if it's necessary to be so minimalistic to disallow doing bad things.
Also, see my old Python experiment on the same topic: https://github.com/machineandme/sneact (it was a joke). TLDR; Python with HTML embeddings. That is a pure Python React-JSX-like library that tests the limits of syntax parser of Python interpreter by "operator overloading".
Flow is a simple and lightweight Go package that provides a chaining mechanism for functions (Functors) that operate on values and errors. It allows you to create chains of functions and apply them to a value, making it easy to implement flexible error handling and value transformation pipelines.
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.