Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
This package is no longer maintained separately. It is now part of ll.xist (http://pypi.python.org/pypi/ll-xist).
ll-core is a collection of the following modules:
ansistyle
can be used for colored terminal output (via ANSI
escape sequences).
color
provides classes and functions for handling RGB color values.
This includes the ability to convert between different color models
(RGB, HSV, HLS) as well as to and from CSS format, and several functions
for modifying and mixing colors.
make
is an object oriented make replacement. Like make it allows you
to specify dependencies between files and actions to be executed
when files don't exist or are out of date with respect to one
of their sources. But unlike make you can do this in a object oriented
way and targets are not only limited to files, but you can implement
e.g. dependencies on database records.
misc
provides several small utility functions and classes.
sisyphus
provides classes for running Python scripts as cron jobs.
daemon
can be used on UNIX to fork a daemon process.
url
contains an RFC2396 compliant implementation of URLs and classes for
accessing resource metadata (like modification dates or permission bits) as
well as file like classes for reading data from URLs and writing data to URLs.
xpit
is a module that makes it possible to embed Python expressions
in text (as XML style processing instructions).
xml_codec
provides a meta codec for decoding XML input.
_xml_codec_include.c
to the source
distributions.FAQs
LivingLogic base package: ansistyle, color, make, sisyphus, xpit, url, xml_codec
We found that ll-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.