
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
@ampproject/toolbox-cache-url
Advanced tools
Supply Chain Security
Vulnerability
Quality
Maintenance
License
Unpopular package
QualityThis package is not very popular.
Found 1 instance in 1 package
Socket optimized override available
Translates an URL from the origin to the AMP Cache URL format, according to the specification available in the AMP documentation. This includes the SHA256 fallback URLs used by the AMP Cache on invalid human-readable cache urls.
Install via:
$ npm install @ampproject/toolbox-cache-url
import {ampToolboxCacheUrl} from '@ampproject/toolbox-cache-url';
const ampToolboxCacheUrl = require('@ampproject/toolbox-cache-url');
In the browser, include the UMD module in an HTML <script>
tag. If using node, replace window
with global
.
const {ampToolboxCacheUrl} = window.ToolboxCacheUrl;
// Get an AMP Cache URL from a cache domain, and a canonical URL
ampToolboxCacheUrl.createCacheUrl('cdn.ampproject.org', 'https://www.example.com').then((cacheUrl) => {
// This would log:
// 'https://www-example-com.cdn.ampproject.org/c/s/www.example.com/'
console.log(cacheUrl);
});
// Transform a canonical URL to an AMP Cache subdomain
ampToolboxCacheUrl.createCurlsSubdomain('https://www.example.com').then((curlsSubdomain) => {
// This would log:
// 'www-example-com'
console.log(curlsSubdomain);
});
FAQs
Transform canonical URLs into AMP Cache URLs
The npm package @ampproject/toolbox-cache-url receives a total of 425 weekly downloads. As such, @ampproject/toolbox-cache-url popularity was classified as not popular.
We found that @ampproject/toolbox-cache-url demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 16 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.