
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
A strategy for working with lambdas.
What it does
This is an opinionated setup for your API, where lambdas reside together. Obviously you could use this and then bring in lambdas as submodules or packages if you wanted to maintain seperate reops.
All assets within the lambda are wrapped up in a ZIP and pushed. Node modules can be easily added. Packages that require more advanced processing may need to be compiled against lambda infrastucture, but this is rare. There are a few built-in Node modules that are available.
This project has a detailed example in ./example
. To run the example, cd
into that directory and npm_install
and run commands from there.
To run a Lambda
node node_modules/lambdakit --run=weather
package.json
(You can omit if your values are the same as these are defaults)."lambdakit": {
"region": "us-east-1",
"path-to-lambdas": "/lib"
}
region
the AWS region where your Lambdas residepath-to-lambdas
is the path to the folder that holds the lambdas. Currently each folder that holds lambda contents needs to match the lambda name in AWS.config.lambdakit.js
for local deploy (You can omit if using local cli config. Contents:process.env.AWS_ACCESS_KEY_ID = 'XXX';
process.env.AWS_SECRET_ACCESS_KEY = 'XXX';
2b. To deploy on commit from your CI server, install credentials on your project in the CI settings. In the case of CircleCI, it’s done with a URI similar to https://circleci.com/gh/myOrg/myProject/edit#aws
.gitignore
to include the following, as your nested lambdas will be projects in and of themselves.**/node_modules/**
/exports/*
/config.aws.lambda.js
FAQs
A strategy for working with lambdas.
The npm package lambdakit receives a total of 2 weekly downloads. As such, lambdakit popularity was classified as not popular.
We found that lambdakit demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.