Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@wddv/baidu-index
Advanced tools
Baidu index sdk for Node.js.
This interface is only available to Baidu Index users for refreshing OAuth access tokens. The access token for accessing the index interface is valid for 24 hours. Before it expires, you can request this interface to obtain a new access token with a validity period of 24 hours. Non-Baidu Index authorized users cannot use this interface to refresh tokens and will receive error code 9016002 (no permission). If more than 24 hours have passed without refreshing through the interface, you will need to manually obtain a token by logging in to the Baidu Index official website and navigating to the API interface section.
Because the token expires after 24 hours, users must obtain a new token from the Baidu Index official website.
I recommend that users save their tokens and request the token refresh interface within 24 hours.
npm install --save @wddv/baidu-index
Node.js verion >= 18
const baiduIndex = new BaiduIndex(
process.env.BAIDU_TOKEN!,
process.env.BAIDU_NAME!
);
const { taskId } = await baiduIndex.createTask({
datasource: 'search',
dateRange: {
start: '2024-04-01',
end: '2024-04-01'
},
device: ['all'],
region: {
province: [],
city: [],
isAll: true
},
keyword: ['小米']
});
const result = await baiduIndex.getResult(taskId);
console.log(result);
FAQs
Baidu index api sdk for Node.js
We found that @wddv/baidu-index demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.