
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
This package bundles the [cbor](../cbor) package for easy use on the web. The following packages are bundled in as well, to reduce the degree of difficulty:
This package bundles the cbor package for easy use on the web. The following packages are bundled in as well, to reduce the degree of difficulty:
In addition, if you want support for big decimal and big float numbers, you'll
need your own version of
bignumber.js. Decoding c4820a0a
(hex) will give you a BigNumber if you have everything installed correctly.
You can see cbor-web
in action on the web here.
cbor
property on the
window object:<script src='https://unpkg.com/bignumber.js'></script> <!-- optional -->
<script src='https://unpkg.com/cbor-web'></script>
require('cbor-web')
from node.js, but I wouldn't recommend that unless you're trying to use the exact same paths for backend and frontend codebases, for example.import cbor from 'cbor-web'
in either node or in some web contexts. Caveats to using in node are the same as above, but someimes you might really want an ES6 module, and be willing to deal with the downsides. Note that as soon as Node 10 is no longer supported, the make cbor
package will work toward becoming a native ES6 module.FAQs
This package bundles the [cbor](../cbor) package for easy use on the web. The following packages are bundled in as well, to reduce the degree of difficulty:
The npm package cbor-web receives a total of 25,756 weekly downloads. As such, cbor-web popularity was classified as popular.
We found that cbor-web demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.