data:image/s3,"s3://crabby-images/9fef7/9fef7e77a4ff9a4c39b8a32ffd7ebda8c2145888" alt="Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy"
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
alamode
is a RegExp-based transpiler of source code in Node.js. It is a fast, low-weight alternative to AST-based transpilers, such as @babel
.
alamode
can be either installed globally, or as a library. The library can be used either programmatically, or via package.json
to refer to a binary in node_modules/.bin
from a yarn
or npm
script.
Install as a global binary from CLI and use to transpile source code files.
Installation Command | Usage Command |
---|---|
npm i -g alamode | yarn build |
|
Install as a dependency and use API to run programmatically in other Node.js software, or access the alamode
binary via a yarn
or npm
script in package.json
.
Installation Command | Usage Command |
---|---|
yarn add -DE alamode npm install alamode --save-dev | node build |
| |
yarn build | npm run build |
|
In the demo below, a project's src
directory is transpiled to replace import
and export
statements and placed in the build
directory.
Using Package.json Script To Transpile |
![]() |
alamode src -o build
The package is available by importing its default function:
import alamode from 'alamode'
alamode(
arg1: string,
arg2?: boolean,
): void
Call this function to get the result you want.
/* yarn example/ */
import alamode from 'alamode'
(async () => {
await alamode()
})()
(c) À La Mode 2018
1.0.3
cdn.rawgit.com
for logos.FAQs
A Regex-Based Transpiler Of Source Code To Allow Writing Import And Export Statements And JSX With 0 Dependencies.
The npm package alamode receives a total of 113 weekly downloads. As such, alamode popularity was classified as not popular.
We found that alamode demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.