data:image/s3,"s3://crabby-images/9fef7/9fef7e77a4ff9a4c39b8a32ffd7ebda8c2145888" alt="Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy"
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
A simple deploy tool inspired by mina, based on minco. This project is powered by node, forcus on quick and lightweight deployment and server automation over ssh for node projects.
Make sure you have installed node.js including NPM
sudo npm install -g mina
Add this to your .bashrc, In this version only support bash
eval "$(mina completion=bash)"
# Create an example deploy.json
mina init
# Adjust it to your needs in deploy.json
{
// Servers to deploy to
"server": ["user@host1","user@host2"]
// Port
, "port": 13
// Deploy to this dir on server
, "server_dir": "/path/to/dir/on/server"
// Git repository, only support git right now
, "repo": "git@github.com:user/repo.git"
// If you have more than one project in your git repo,
// e.g. "projects/project_luna"
, "prj_git_relative_dir": ""
// Branch to be checkout and deploy
, "branch": "master"
// If remove git cloned directory then git clone again,
// default is false
, "force_regenerate_git_dir": false
// Directories of your project in this array will use a
// symbolic instead create every time when run deploy
, "shared_dirs": ["node_modules", "db"]
// How many release snapshots keep away from auto cleanup,
// default is 10 if not presents
, "history_releases_count": 10
// Run customize scripts before run
, "prerun": [
"npm install",
"npm test"
]
// Start run your project
, "run_cmd": "npm start"
}
# Deploy
mina deploy
# Or, indicate deploy config file
MINA_CONFIG=deploy_scripts/to_dev.json mina deploy
git clone
, that's means git-core
must be installed, and, can clone the project from you git-repo.FAQs
Lightweight deployer for node development, inspired by mina and minco
The npm package mina receives a total of 4 weekly downloads. As such, mina popularity was classified as not popular.
We found that mina demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.