Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
calamarcopollo
Advanced tools
Save The Chicken Foundation
CalamarcoPollo project is a chatbot for consulting intercity bus schedules in Brazil using Brazilian Portuguese natural language queries and conversations.
This project is also a real-world app used to improve and test the, still very alpha CalaMars framework.
If you have Telegram installed, add the @calamarcopollo_demo_bot to your contacts and try to talk to it.
If you have Facebook, use this fb messenger link, or if you use the mobile Facebook Messenger app, scan the image below:
For inspiration of what the pollo is capable of, try one of the sample statements.
mkdir mybot
cd mybot
npm install calamarcopollo@latest
cp node_modules/calamarcopollo/.env-sample .env
# fill-in the blanks
source .env
`npm bin`/pollo
In the .env
file, you can setup a path with a javascript module to override
any of the default reply strings, this custom path is stored
in the CUSTOM_REPLIES_PATH
environment var.
You can copy the replies/custom.js
file to use it as basis for your replacements:
cp node_modules/calamarcopollo/replies/custom.js ./custom-replies.js
# edit .env file to add the absolute path to custom-replies.js file as value
# for the CUSTOM_REPLIES_PATH variable
source .env
Copyright (c) 2016 Fabricio C Zuardi
This software is distributed under the GNU AFFERO GENERAL PUBLIC LICENSE version 3.
FAQs
Save the chicken foundation
We found that calamarcopollo demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.