
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
idspy is a simple and easy-to-use networking tool designed to simplify basic tasks. This command-line utility provides information about your current network and host, along with fetching public IP data.
The utility is written in Node.js and is deployable on any system supporting Node.js.
Make sure you have Node.js installed on your system. Then, install idspy globally using npm:
npm install -g idspy
To fetch host data, simply run the command without any arguments:
idspy
This will output information about your current host, including the username, device name, CPU, OS, total memory, private IP address, and public IP address.
To fetch IP data, pass an IP address as an argument:
idspy 8.8.8.8
This will output information related to the IP address, including the city, region, country, ZIP, and ISP.
idspy can identify IPv4 and IPv6 addresses as well as domains. If the input is not recognized as any of these, an error message will be shown with information on the correct formats.
Feel free to contribute to this project by submitting issues or pull requests for bugs and features.
MIT License
Please use this tool responsibly. Fetching public IP data is meant for legitimate use cases like debugging and troubleshooting.
FAQs
npm packge to streamline simple networking and OSINT tasks
We found that idspy demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.