data:image/s3,"s3://crabby-images/9fef7/9fef7e77a4ff9a4c39b8a32ffd7ebda8c2145888" alt="Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy"
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
If you need a system easy to use that provides you a periodic (or at specific time) backup. This is your package.
Right now this package is tested only on Ubuntu 20.04 LTS and you need to have the following packages in order to work:
sudo apt install zip
100.5.2
Configuration is split in 3 steps:
mongo
: backup your database from MongoDBfile
: choose files from your system to backuptelegram
: uses a channel and a bot to notify all your backupsconsole
: just print to consolegcp
: Google Cloud Storagefile
: drop it somewhere in your system (soon)Use following examples (backup engines, notificator, uploader) to make your own config file, here is the skeleton:
{
"cron": "* * * * * *", // Cron schedule expression (https://crontab.guru)
"outputDir": "/tmp", // Temporary folder to store your backup until upload
"engine": { ... }// Backup engine config,
"notificator": { ... }// Notificator config,
"uploader": { ... }// Uploader config
}
{
"type": "mongo",
"databaseHost": "", // Host name of your MongoDB
"databasePort": 27017, // [Optional] Database port. Defaults to 27017
"databaseName": "",
"username": "" // [Optional] In case that your DDBB needs auth
"password": "" // [Optional]
}
{
"type": "file",
"path": "" // Path to drop out the zipped backup
}
{
"type": "telegram",
"chatId": "", // ID of the chat where you want to be notified
"botToken": "" // Token ID (without "bot" prefix in case that have) (https://core.telegram.org/bots)
}
Note: You can obtain the chatId from this URL: https://api.telegram.org/bot/getUpdates. Substitute <putYourToken>
with your bot token
{
"type": "console"
}
{
"type": "gcp",
"storageKeyPath": "", // JSON Key file that authenticate your program on GCP
"backupsFolderPath": "", // [Optional] Name of the folder inside the bucket to put the backup. Defaults to "backups"
"bucketName": "",
"projectId": ""
}
FAQs
Backup tool to make it easy
The npm package ec-backup receives a total of 9 weekly downloads. As such, ec-backup popularity was classified as not popular.
We found that ec-backup demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.