Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@travetto/exec
Advanced tools
Common wrapper around process execution with high level docker support.
The exec module provides the necessary foundation for calling executables at runtime. Additionally special attention is provided to running docker
containers.
Just like child_process
, the module exposes spawn
, fork
, and exec
. These are generally wrappers around the underlying functionality. In addition to the base functionality, each of those functions is converted to a Promise
structure, that throws an error on an non-zero return status.
A simple example would be
async function executeListing() {
const [process, resultPromise] = spawn('ls');
await resultPromise;
}
As you can see, the call returns not only the child process information, but the Promise
to wait for. Additionally, some common patterns are provided for the default construction of the child process. In addition to the standard options for running child processes, the module also supports:
timeout
as the number of milliseconds the process can run before terminating and throwing an errorquiet
which suppresses all stdout/stderr outputstdin
as a string, buffer or stream to provide input to the program you are running;timeoutKill
allows for registering functionality to execute when a process is force killed by timeoutNode provides ipc functionality out of the box, and this module builds upon this by providing enhanced event management functionality, as well as constructs for orchestrating multi-step processes.
Docker provides a unified way of executing external programs with a high level of consistency and simplicity. For that reason, the framework leverages this functionality to provide a clean cross-platform experience. The docker functionality allows you to interact with containers in two ways:
Shutdown
of the application.async function runMongo() {
const port = 10000;
const container = new DockerContainer('mongo:latest')
.createTempVolume('/var/workspace')
.exposePort(port)
.setWorkingDir('/var/workspace')
.forceDestroyOnShutdown();
container.run('--storageEngine', 'ephemeralForTest', '--port', port);
await DockerContainer.waitForPort(port);
return;
}
While docker containers provide a high level of flexibility, performance can be an issue. CommandService
is a construct that wraps execution of a specific child program. It allows for the application to decide between using docker to invoke the child program or calling the binary against the host operating system. This is especially useful in environments where installation of programs (and specific versions) is challenging.
const converter = new CommandService({
image: 'agregad/pngquant',
checkForLocal: async () => {
return (await spawn('pngquant -h')[1]).valid;
}
});
async function compress(img) {
const [proc, prom] = await converter.exec('pngquant', '--quality', '40-80', '--speed 1', '--force', '-');
const out = `${img}.compressed`;
fs.createReadStream(img).pipe(proc.stdin);
proc.stdout.pipe(fs.createWriteStream(out));
await prom;
}
With respect to managing multiple executions, ExecutionPool
is provided to allow for concurrent operation, and processing of jobs as quickly as possible.
To manage the flow of jobs, there are various DataExecutionSource
implementation that allow for a wide range of use cases.
The supported DataExecutionSource
s are
Array
is a list of jobs, will execute in order until list is exhausted.Queue
is similar to list but will execute forever waiting for new items to be added to the queue.Iterator
is a generator function that will continue to produce jobs until the iterator is exhausted.Below is a pool that will convert images on demand, while queuing as needed.
class ImageProcessor {
active = false;
proc: ChildProcess;
kill() {
this.proc.kill();
}
async convert(path: string) {
this.active = true;
try {
this.proc = ...convert ...
await this.proc;
} catch (e) {
}
this.active = false;
}
}
class ImageCompressor {
pendingImages: QueueExecutionSource<string>;
pool = new ExecutionPool(async () => {
return new ImageProcessor();
});
constructor() {
this.pool.process(this.pendingImages, async (inp, exe) => {
exe.convert(inp);
});
}
convert(...images: string[]) {
for (const img of images) {
this.pendingImages.enqueue(img);
}
}
}
FAQs
Common wrapper around process execution with high level docker support.
We found that @travetto/exec demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.