Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
github.com/young-zhang/windowsiana
A very simple package that helps when dealing with Windows timezones and mapping them to standard timezones.
I created this package to handle times that were sent back from a web service that were sent with details of the Windows timezone to which they were tied. In order to make the time usable in Go, I created this little package to allow me to convert an inbound Windows time into a propert time.
The list is also inspired by the Microsoft Graph API and as of 21st of May 2019 is compatible to all outlookUser supportedTimeZones
The program is as of 07/2021 developed with Visual Studio Code and several plugins. For enhanced compatibility and easier upgrading, golang is not installed locally anymore, but instead used via a docker container. Therefore the following may be installed on the development machine to develop without a local golang installation:
The list is also inspired by the Microsoft Graph API and as of 21st of July 2021 is compatible to all outlookUser supportedTimeZones
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.