Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Add the latest version of bithound
to your package.json:
npm install bithound --save-dev
This script bin/bithound
provides two cli commands:
check (git url || repo token)
Checks bitHound for failing files or dependencies.
token
Opens your browser to the repo settings page of the current project.
If you include node_modules/.bin
in your $PATH
, you can run this cli with:
bithound <command>
Otherwise, run it with:
./node_modules/.bin/bithound <command>
Attempts to retrieve the latest status of failing criteria for a repo.
This command can be used to check the status of both public and private repos.
For public repos, use the raw git url of the repo. It will look similar to:
git@github.com:bithound/cli.bithound.io.git
For private repos, use your repo token provided by bitHound. It will look similar to:
8164a970-c6bb-11e5-9058-dd9db6223fa8
See the token
command for how to get this value.
Run the check command as follows:
bithound check <git url | repo token>
You may optionally pass the specific branch and sha through the --branch
and --sha
options, respectively. However, this is
designed to work inside a CI and, as such, the check
command will attempt to pick up the branch and sha from the CI environment variables
when a push event is detected by the CI.
If analysis is in progress, this command will poll until analysis is complete and report the results.
Your repo token can be found on your repo settings page under Integrations or by running bithound token
. In addition, you may also configure your repo's failing criteria on that settings page.
bithound token
This command takes you to your Integrations section of the repo settings page for the repo that bitHound is currently found to be a dependency of. Think of it as a shortcut to discovering your repo token.
Please note: This command requires git to be installed in order to properly identify the repo remote origin.
FAQs
Commands for interacting with bitHound: https://bithound.io
The npm package bithound receives a total of 1,479 weekly downloads. As such, bithound popularity was classified as popular.
We found that bithound demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.