Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
bundlecamper-xbox-live-module
Advanced tools
An NPM for fetching xbox live player data
First include the module:
var XBoxLive = require('xbox-live');
then, instantiate the object:
var api = new XBoxLive();
now you can fetch a profile:
api.fetch('profile', 'Major+Nelson', function(err, data){
//do stuff
});
or games:
api.fetch('games', 'Major+Nelson', function(err, data){
//do stuff
});
or friends:
api.fetch('friends', 'Major+Nelson', function(err, data){
//do stuff
});
or achievements (for a particular xbl game id):
api.fetch('achievements', 'Major+Nelson', 1096157139, function(err, data){
//do stuff
});
In an attempt to be less prone to breakage there are two sources: the default, xboxleaders.com and xboxapi.com, which seems to enforce stricter limits. If more pop up, I will likely add them, too. xboxleaders has been updated to their new format, but be warned: their service has become extremely flakey and when it fails, it claims the user doesn't exist on XBL :P but it's up-to-date with less dependencies.
Run the tests at the project root with:
mocha
Enjoy,
-Abbey Hawk Sparrow
FAQs
A utility for fetching xbox live gamer data
The npm package bundlecamper-xbox-live-module receives a total of 1 weekly downloads. As such, bundlecamper-xbox-live-module popularity was classified as not popular.
We found that bundlecamper-xbox-live-module demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.