data:image/s3,"s3://crabby-images/9fef7/9fef7e77a4ff9a4c39b8a32ffd7ebda8c2145888" alt="Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy"
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
DEPRECATED: Reverend
has been deprecated and will no longer see updates. The underlying module used to create regular expressions from routes—path-to-regexp—has added reverse-routing functionality. Please favor it over Reverend
. An api-compatible shim can be seen in the shim branch.
Lead Maintainer: Jean-Charles Sisk
Merge an express-style path string with data to create a valid path. Version 0.3.x adds support for Custom Match and Unnamed parameters as provided by path-to-regexp ^0.2.0. To ensure compatibility, use the version of reverend compatible with path-to-regexp which most closely matches the version your application uses.
var reverend = require('reverend');
path
(String|Array) - An express-style path, or an array of paths, of which only the first element will be used.object
(Object) - An object with keys matching the tokens to be replaced in the route.'use strict';
var reverend = require('reverend');
var path;
// Path params
path = reverend('/user/:id', { id: 5 });
// '/user/5';
// Optional path params
path = reverend('/user/:id/:operation?', { id: 5 });
// '/user/5/';
// Multiple path params
path = reverend('/user/:id/:operation', { id: 5, operation: address });
// '/user/5/address';
// Custom match parameters
path = reverend('/posts/:id(\\d+)', { id: 5 });
// '/post/5'
path = reverend('/posts/:id(\\d+)', { id: 'foo' }); // throws
// Unnamed params
path = reverend('/:foo/(.*)', { foo: 'foo', 0: 'bar' });
// '/foo/bar'
MIT
$ npm test
$ npm run cover
$ npm run lint
FAQs
Merge an express-style path string with data to create a valid path.
The npm package reverend receives a total of 299 weekly downloads. As such, reverend popularity was classified as not popular.
We found that reverend demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.