
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
intelmq-webinput-csv
Advanced tools
This is a simple web interface allowing the user to insert data into intelmq's pipelines interactively with preview from the parser.
A web interface for interactively inserting one-off CSV data into IntelMQ's pipelines.
It is implemented in Python with hug in the backend and Javascript with bootstrap-vue in the frontend. This is a rewrite of the original Flask-based web interface by CERT.at.
To get the Webinput-CSV up and running, clone the repo and use
$ pip3 install .
$ hug -f intelmq_webinput_csv/serve.py -p 8002
For more details see the Installation guide.
The Webinput-CSV can be started with default values and is fully usable (except of the injection in the IntelMQ pipeline queue). Most parameters for the input are available in the Frontend and are self explaining.
For detailed description of configuration and parameters see the user guide.
hug provides an auto-refresh development mode when starting the application using
$ hug -f intelmq_webinput_csv/serve.py -p 8002
Like hug, yarn provides this for the client using
$ cd client
$ yarn && yarn serve
For detailed developer information and how to develop with docker see developer guide
This software is licensed under GNU Affero General Public License version 3.
FAQs
This is a simple web interface allowing the user to insert data into intelmq's pipelines interactively with preview from the parser.
We found that intelmq-webinput-csv demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.