Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
npm install ggis
Note: You'll need to set up your own Google Custom Search Engine to execute queries.
const GoogleSearch = require('ggis')
const shrek = new GoogleSearch('CSE ID', 'API KEY');
shrek.search('shrek memes') //
.then(images => {
/*
[{
"url": "http://steveangello.com/boss.jpg",
"type": "image/jpeg",
"width": 1024,
"height": 768,
"size": 102451,
}
}]
*/
});
// paginate results
shrek.search('my big and dirty swamp', {startingPage: 5 , nPages: 5}); // by default {startingPage : 1, nPages : 1}
// search for certain size
shrek.search('Shrek 5', {size: 'large'});
Please see Google's API documentation for details on the option and response properties and their possible values.
Type: string
The identifier for a Custom Search Engine to use.
Type: string
The credentials for accessing Google's API.
Perform an image search for query
.
Type: string
The search terms to use for finding images. Identical to those you would use in a web search.
Type: object
Type: number
Default: 1
Sets the starting page from which you will get result E.g {startingPage : 2}
will skip the results from page 1.
Type: number
Default: 1
Sets the number of pages you wish to return. Note that 1 page holds 10 results.
See the Google's API documentation for the following parameters.
Type: string
The category of images to search. E.g. face
or photo
.
Type: string
The category of color spectrums to search. E.g. gray
or color
.
Type: string
The dominant color to search for. E.g. yellow
or purple
.
Type: string
The size of images to search. E.g. medium
or xxlarge
.
Google deprecated their public Google Images API, so to search for images you need to sign up for Google Custom Search Engine. Here are the steps you need to do:
You can do this here: https://cse.google.com/cse.
Do not specify any sites to search but instead use the "Restrict Pages using Schema.org Types" under the "Advanced options".
For the most inclusive set, use the Schema: Thing
. Make a note of the CSE ID.
In your search engine settings, enable "Image search":
Register a new app and enable Google Custom Search Engine API here: Google Developers Console. Make a note of the API key.
FAQs
Small mmodule to request images from google search
The npm package ggis receives a total of 1 weekly downloads. As such, ggis popularity was classified as not popular.
We found that ggis demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.