Research
Security News
Malicious PyPI Package ‘pycord-self’ Targets Discord Developers with Token Theft and Backdoor Exploit
Socket researchers uncover the risks of a malicious Python package targeting Discord developers.
This project contains source code and supporting files for a serverless application that you can deploy with CDK.
This is a deployable CDK app that deploys AWS Lambda functions as part of a CloudFormation stack. These Lambda functions use the utilities made available as part of AWS Lambda Powertools for TypeScript to demonstrate their usage.
Note You will need to have a valid AWS Account in order to deploy these resources. These resources may incur costs to your AWS Account. The cost from some services are covered by the AWS Free Tier but not all of them. If you don't have an AWS Account follow these instructions to create one.
The example functions, located in the functions
folder, are frontend by a REST API that is deployed using AWS API Gateway.
The API has three endpoints:
POST /
- Adds an item to the DynamoDB tableGET /
- Retrieves all items from the DynamoDB tableGET /{id}
- Retrieves a specific item from the DynamoDB tableexamples/cdk
)npm ci
npm run cdk deploy --all --profile <YOUR_AWS_PROFILE>
Note: Prior to deploying you may need to run cdk bootstrap aws://<YOU_AWS_ACCOUNT_ID>/<AWS_REGION> --profile <YOUR_AWS_PROFILE>
if you have not already bootstrapped your account for CDK.
Note You can find your API Gateway Endpoint URL in the output values displayed after deployment.
Use the API Gateway Endpoint URL from the output values to execute the functions. First, let's add two items to the DynamoDB Table by running:
curl -XPOST --header 'Content-Type: application/json' --data '{"id":"myfirstitem","name":"Some Name for the first item"}' https://randomid12345.execute-api.eu-central-1.amazonaws.com/prod/
curl -XPOST --header 'Content-Type: application/json' --data '{"id":"myseconditem","name":"Some Name for the second item"}' https://randomid1245.execute-api.eu-central-1.amazonaws.com/prod/
Now, let's retrieve all items by running:
curl -XGET https://randomid12345.execute-api.eu-central-1.amazonaws.com/prod/
And finally, let's retrieve a specific item by running:
curl -XGET https://randomid12345.execute-api.eu-central-1.amazonaws.com/prod/myseconditem/
If we check the logs in CloudWatch, we can see that the logs are structured like this
2022-04-26T17:00:23.808Z e8a51294-6c6a-414c-9777-6b0f24d8739b DEBUG
{
"level": "DEBUG",
"message": "retrieved items: 0",
"service": "getAllItems",
"timestamp": "2022-04-26T17:00:23.808Z",
"awsRequestId": "e8a51294-6c6a-414c-9777-6b0f24d8739b"
}
By having structured logs like this, we can easily search and analyse them in CloudWatch Logs Insight. Run the following query to get all messages for a specific awsRequestId
:
filter awsRequestId="bcd50969-3a55-49b6-a997-91798b3f133a"
| fields timestamp, message
As we have enabled tracing for our Lambda-Funtions, you can visit AWS CloudWatch Console and see Traces and a Service Map for our application.
To delete the sample application that you created, run the command below while in the examples/cdk
directory:
cdk destroy
FAQs
This project contains source code and supporting files for a serverless application that you can deploy with CDK.
The npm package cdk-sample receives a total of 0 weekly downloads. As such, cdk-sample popularity was classified as not popular.
We found that cdk-sample demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover the risks of a malicious Python package targeting Discord developers.
Security News
The UK is proposing a bold ban on ransomware payments by public entities to disrupt cybercrime, protect critical services, and lead global cybersecurity efforts.
Security News
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.