New Research: Supply Chain Attack on Axios Pulls Malicious Dependency from npm.Details →
Socket
Book a DemoSign in
Socket

loas

Package Overview
Dependencies
Maintainers
1
Versions
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

loas

Google Low Overhead Authentication Service (LOAS) client stub — security research canary (Google VRP)

pipPyPI
Version
9.9.9
Maintainers
1

loas

Security Research Canary — Google VRP Dependency Confusion Test

Registered by Michael Hyndman as part of authorized Google Vulnerability Reward Programme research. This package only phones home on import. No malicious code. No persistent processes. No data exfiltration.

Technique: Dependency Confusion (Alex Birsan, 2021)

FAQs

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts