
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
autohost-canary
Advanced tools
Adds an end-point for tracking in-depth status of a service. Services determine what gets reported as status via API.
npm install autohost-canary -S
var autohost = require( "autohost" );
var host;
var hyped = require( "hyped" )();
var fount = require( "fount" );
var postal = require( "postal" );
// create the channel used to communicate between
// various components and the status tracker
var channel = postal.channel( "ahcanary" );
fount.register( "ahcanary", channel );
host = hyped.createHost( autohost, {
port: config.nonstop.host.port,
modules: [
"autohost-canary"
],
fount: fount
}, function() {
host.start();
} );
// by publishing a status to a topic, the status tracker will update its state
// where topic is the key and the message will be the value. This is a very simple
// way to get a quick glimpse into what's happening. See status messages for more
// details on how to control status.
// this example demonstrates tracking rabbit connectivity:
rabbit.on( "connected", function( msg ) {
channel.publish( "rabbit", { value: "connected" } );
} );
rabbit.on( "closed", function( msg ) {
channel.publish( "rabbit", { value: "closed" } );
} );
rabbit.on( "failed", function( msg ) {
channel.publish( "rabbit", { value: "connection failed" } );
} );
The only thing you can do is get the status:
GET /api/ah/status
If you're using hyped
then you can access the same endpoint via status:self
. The names and routes were chosen to make the chance of collision extremely low.
The result will be a JSON object with your keys/values and a few bonus items:
{
// your stuff here ...
"memory": { a hash containing memory usage details },
"uptime": "a human readable duration",
"version": "a version specifier from your package.json OR nonstop-info"
}
You get a little more control on what status is reported based on how you format your message.
You can publish a message with default
to tell canary that if the key is removed or reset to still display the key with the default value.
channel.publish( "database", { default: "pending" } );
Publishing this message will cause the key to revert to undefined or a previously provided default value.
channel.publish( "key", { reset: true } );
Updates the current status for the topic to the value provided.
channel.publish( "usersConnected", x );
Some values are only good for a period of time or don't have a compensating event to tell you when the value has changed. To address this, you can put a ttl
property on the message body which will cause the value to be removed from status or revert to a previously assigned default.
channel.publish( "processingMessages", value: true, ttl: 100 )
FAQs
An endpoint for getting service status updated via postal
The npm package autohost-canary receives a total of 0 weekly downloads. As such, autohost-canary popularity was classified as not popular.
We found that autohost-canary demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.