
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
coffeepy
Advanced tools
Coffeepy ☕️ is a small program that prevents the system from sleeping. Works on MacOS, Windows and Linux.
pip install -U coffeepy
Simply run the program from command line
coffeepy
By default the program runs indefinitely. Press Ctrl-C to quit
Optional: You can set the time in minutes with -t or --time flag. For example, to run the program for 1 hour, use
coffeepy -t 60
You can also disable animation with -a or --no-animation flag.
coffeepy -a
You can view the full parameter list with -h or --help.
You can also import coffeepy as a python module
import coffeepy
coffeepy.run()
Optional settings when run as a python module:
import coffeepy
# you can also specify the time in minutes
# if no time is provided or time = 0, the program will run indefinitely
coffeepy.run(60)
# to disable animation when run as a module, you can set the second argument to True
coffeepy.run(0, True)
This project is licensed under the MIT License
FAQs
Coffeepy prevents the system from sleeping
We found that coffeepy demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.