
Research
npm Malware Targets Telegram Bot Developers with Persistent SSH Backdoors
Malicious npm packages posing as Telegram bot libraries install SSH backdoors and exfiltrate data from Linux developer machines.
This is an OAuth 2.0 client library and WSGI middleware filter.
New pseudo release to keep in sync with ndg_oauth_server package versioning. No changes from 0.4.0. New ndg_oauth_server 0.5.1 contains enhancements from W van Engen including support for password based authentication for clients. See ndg_oauth_server package for details.
This has been developed and tested for Python 2.6 and 2.7.
Installation can be performed using easy_install or pip.
Examples are contained in the examples/ sub-folder:
bearer_tok/: This configures a simple test application that uses string based tokens. slcs/: Bearer token example protecting a Short-Lived Credential Service or OnlineCA. ContrailOnlineCAService package is needed for this example.
The examples should be used in conjunction with the ndg_oauth_server package.
FAQs
OAuth 2.0 client
We found that ndg-oauth-client demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Malicious npm packages posing as Telegram bot libraries install SSH backdoors and exfiltrate data from Linux developer machines.
Security News
pip, PDM, pip-audit, and the packaging library are already adding support for Python’s new lock file format.
Product
Socket's Go support is now generally available, bringing automatic scanning and deep code analysis to all users with Go projects.