
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
@valu/npm-tools
Advanced tools
Scripts to manage releases on this and other repos
npm install -g @valu/npm-tools
valu-npm-prerelease
Run in a packages/*
directory to make prerelease of that package
valu-npm-release
Run in a packages/*
directory to make stable release of that package
valu-npm-dev-install
Install unpublished package to a project
cd project
valu-npm-dev-install /path/to/npm-packages/packages/a-package
You can use -f
to install the package without building it first.
This is useful when using a watcher to build the package automatically.
cd /path/to/npm-packages/packages/a-package
npm run watch
cd project
valu-npm-dev-install -f /path/to/npm-packages/packages/a-package
FAQs
Tools for working with npm packages
We found that @valu/npm-tools demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.