
Research
Malicious Go “crypto” Module Steals Passwords and Deploys Rekoobe Backdoor
An impersonated golang.org/x/crypto clone exfiltrates passwords, executes a remote shell stager, and delivers a Rekoobe backdoor on Linux.
pg-migration
Advanced tools
Apply changesets of your data structure for Postgresql easily from your node application
NodeJS lacks support for good proper ORMs, and most ORMs tend to suck a bit in the end anyway. For inventid I therefore developed this simple nodejs version for postgresql of Liquibase. It is based on the excellent node-postgres library.
pg-migration will automatically create the table (dbchangelog) for you.
import migration from 'pg-migration';const migrateAndStart = migration({ log: (level, message) => { your logging code here } })migrateAndStart(db, './migrations', startServer);)Files called README.md and dbchangelog.sql from the migrations folder are ignored.
Since the changeset id is derived from the file name, you can use the following command to create a new one
touch `date +%Y%m%d%H%M%S`.sql
Please be careful that the files will be executed in a alphabetically sorted fashion, so ensure that files do not depend on anything later (it's really a poor mans Liquibase).
FAQs
Apply changesets of your data structure for Postgresql easily from your node application
The npm package pg-migration receives a total of 0 weekly downloads. As such, pg-migration popularity was classified as not popular.
We found that pg-migration demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
An impersonated golang.org/x/crypto clone exfiltrates passwords, executes a remote shell stager, and delivers a Rekoobe backdoor on Linux.

Security News
npm rolls out a package release cooldown and scalable trusted publishing updates as ecosystem adoption of install safeguards grows.

Security News
AI agents are writing more code than ever, and that's creating new supply chain risks. Feross joins the Risky Business Podcast to break down what that means for open source security.