Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Avulto is a Python library for working in the BYOND environment. Its goal is to provide a straightforward Python API which leverages the SpacemanDMM and potentially other community libraries.
Its primary use cases are to easily
Avulto is available as a release on PyPI. See the Development section below for directions on using the library locally.
A Quickstart and the API reference are available at the library's documentation site
and in the docs/
directory of the repository. Its API is documented in full in its stub file.
Avulto is written in Rust and implemented using PyO3, and uses maturin for development. To build and install locally:
$ python -m maturin build; python -m pip install .
$ python -m pytest
Avulto is licensed under the GPL. See LICENSE
for more information.
Portions of Avulto are originally based on SpacemanDMM, copyright Tad Hardesty and licensed under the GPL.
Portions of Avulto are originally based on StrongDMM, copyright SpaiR and licensed under the GPL.
FAQs
A Python API for working with BYOND projects.
We found that avulto demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.