Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@tedconf/fessonia
Advanced tools
A node module easing the burden of automating ffmpeg from node.js
Fessonia is a node module for working with FFmpeg, allowing for modeling inputs, outputs, filtergraphs, and entire ffmpeg commands in JavaScript code.
For a quick intro to the library, take a look at the Getting Started with Fessonia tutorial.
For an introduction to the design approach of the library, the goals, and other assorted information, take a look at the About Fessonia doc.
Your contributions are welcome! To get started developing on this library, take a look at the Contributing doc.
A big thanks goes to all those who have already contributed!
This project was made with ♥️ by TED, and is licensed under the MIT license. For more details, see the License file.
FAQs
A node module easing the burden of automating ffmpeg from node.js
We found that @tedconf/fessonia demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.