
Research
/Security News
11 Malicious Go Packages Distribute Obfuscated Remote Payloads
Socket uncovered 11 malicious Go packages using obfuscated loaders to fetch and execute second-stage payloads via C2 domains.
支持 yarn、pnpm、npm、bun
npm install -g ccommand # 安装ccommand install ccommand
ccommand -v # 查看版本 view version
ccommand find # 查找workspace find workspace
ccommand # 执行当前script Execute the current script
ccommand -help # 查看帮助 view help
# 导出环境变量在你的bash或者zsh中 Export environment variables in your bash or zsh
# 中文 Chinese
export PI_Lang=zh
# 英文 English
export PI_Lang=zh
when you run command with search the quick command will be output with tips 当你使用命令通过查找执行, 会在终端输出一个快速执行命令的提示
FAQs
ccommand
We found that ccommand demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Socket uncovered 11 malicious Go packages using obfuscated loaders to fetch and execute second-stage payloads via C2 domains.
Security News
TC39 advances 11 JavaScript proposals, with two moving to Stage 4, bringing better math, binary APIs, and more features one step closer to the ECMAScript spec.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).