
Research
Malicious Go “crypto” Module Steals Passwords and Deploys Rekoobe Backdoor
An impersonated golang.org/x/crypto clone exfiltrates passwords, executes a remote shell stager, and delivers a Rekoobe backdoor on Linux.
CLI to help you hit the ground running without any sign-up. Instantiate a database with a single-command!
Note: This package was previously named
neondb. The old package is now deprecated. If you're upgrading fromneondb, simply replace it withget-dbin your commands and imports.
npx get-db
npx get-db [options]
Options:
-y, --yes Use defaults, skip prompts-e, --env Path to .env file (default: ./.env)-k, --key Env key for connection string (default: DATABASE_URL)-p, --prefix Prefix for public env vars (default: PUBLIC_)-s, --seed Path to SQL file to execute after database creation-h, --help Show helpImport the SDK:
import { instantNeon } from "get-db/sdk";
Create a claimable Neon Postgres database and save credentials to your .env:
await instantNeon({
dotEnvFile: ".env",
dotEnvKey: "DATABASE_URL",
envPrefix: "PUBLIC_",
// This below is to help us understand where usage comes from.
// If you're publishing a library, we'd love that you re-expose a
// referrer parameter in your lib and set this to `npm:your-lib-package-name|${referrer}`
// So we can understand the chain better and give you all the credit you deserve!
referrer: "npm:your-cli-package-name",
});
| Option | Default | Description | Validation |
|---|---|---|---|
| dotEnvFile | ".env" | Path to env file | letters and . |
| dotEnvKey | "DATABASE_URL" | Environment variable name | `SCREAMING_SNAKE_CASE |
| envPrefix | "PUBLIC_" | Prefix for public environment vars | - |
| referrer | "unknown" | Referrer identifier | - |
Note: The Vite plugin uses
VITE_as the defaultenvPrefixto match Vite's convention for client-side environment variables.
Returns:
| Property | Description |
|---|---|
databaseUrl | connection string |
poolerUrl | pooled connection string |
claimUrl | claim link |
claimExpiresAt | expiration date |
// Params for instantNeon
interface InstantNeonParams {
dotEnvFile?: string;
dotEnvKey?: string;
envPrefix?: string;
referrer?: string;
}
See documentation on Neon for more.
This package was templated with create-typescript-app using the Bingo engine.
FAQs
create a claimable Neon database in seconds!
The npm package get-db receives a total of 1,380 weekly downloads. As such, get-db popularity was classified as popular.
We found that get-db demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
An impersonated golang.org/x/crypto clone exfiltrates passwords, executes a remote shell stager, and delivers a Rekoobe backdoor on Linux.

Security News
npm rolls out a package release cooldown and scalable trusted publishing updates as ecosystem adoption of install safeguards grows.

Security News
AI agents are writing more code than ever, and that's creating new supply chain risks. Feross joins the Risky Business Podcast to break down what that means for open source security.