
Research
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.
github.com/whois-api-llc/ip-netblocks-go
Advanced tools
The client library for IP Netblocks API in Go language.
The minimum go version is 1.17.
The library is distributed as a Go module
go get github.com/whois-api-llc/ip-netblocks-go
Full API documentation available here
You can find all examples in example directory.
To start making requests you need the API Key. You can find it on your profile page on whoisxmlapi.com. Using the API Key you can create Client.
Most users will be fine with NewBasicClient function.
client := ipnetblocks.NewBasicClient(apiKey)
If you want to set custom http.Client to use proxy then you can use NewClient function.
transport := &http.Transport{Proxy: http.ProxyURL(proxyUrl)}
client := ipnetblocks.NewClient(apiKey, ipnetblocks.ClientParams{
HTTPClient: &http.Client{
Transport: transport,
Timeout: 20 * time.Second,
},
})
IP Netblocks API lets you get exhaustive information on the IP range that a given IP address belongs to.
// Make request to get all parsed IP netblocks (inetnums) by IP address
ipNetblocksResp, resp, err := client.GetByIP(ctx, []byte{8,8,8,8})
if err != nil {
log.Fatal(err)
}
for _, obj := range ipNetblocksResp.Result.Inetnums {
log.Printf("Netblock: %s, Time: %s, ASN: %s\n",
obj.Inetnum,
time.Time(obj.Modified).Format(time.RFC3339),
obj.AS.ASN,
)
}
// Make request to get raw IP Netblocks data by autonomous system number
resp, err := client.GetRawByASN(context.Background(), 15169)
if err != nil {
log.Fatal(err)
}
log.Println(string(resp.Body))
FAQs
Unknown package
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.