
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
passagemath: Sage objects, elements, parents, categories, coercion, metaclasses
Supply Chain Security
Vulnerability
Quality
Maintenance
License
passagemath <https://github.com/passagemath/passagemath>
__ is open
source mathematical software in Python, released under the GNU General
Public Licence GPLv2+.
It is a fork of SageMath <https://www.sagemath.org/>
__, which has been
developed 2005-2025 under the motto “Creating a Viable Open Source
Alternative to Magma, Maple, Mathematica, and MATLAB”.
The passagemath fork was created in October 2024 with the following goals:
major project started in 2020 in the Sage codebase <https://github.com/sagemath/sage/issues/29705>
__,clear attribution of upstream projects <https://groups.google.com/g/sage-devel/c/6HO1HEtL1Fs/m/G002rPGpAAAJ>
__,platform portability and integration testing services <https://github.com/passagemath/passagemath/issues/704>
__
to upstream projects,building a professional, respectful, inclusive community <https://groups.google.com/g/sage-devel/c/xBzaINHWwUQ>
__,Pyodide <https://pyodide.org/en/stable/>
__ for
serverless deployment with Javascript,Full documentation <https://doc.sagemath.org/html/en/index.html>
__ is
available online.
passagemath attempts to support all major Linux distributions and recent versions of macOS. Use on Windows currently requires the use of Windows Subsystem for Linux or virtualization.
Complete sets of binary wheels are provided on PyPI for Python versions 3.9.x-3.12.x. Python 3.13.x is also supported, but some third-party packages are still missing wheels, so compilation from source is triggered for those.
The pip-installable distribution package sagemath-objects
is a
distribution of a small part of the Sage Library.
It provides a small, fundamental subset of the modules of the Sage library
("sagelib", sagemath-standard
), making Sage objects, the element/parent
framework, categories, the coercion system and the related metaclasses
available.
When building from source, development packages of gmp
, mpfr
, and mpc
are needed.
Categories <https://doc.sagemath.org/html/en/reference/categories/index.html>
_
Structure <https://doc.sagemath.org/html/en/reference/structure/index.html>
_
Coercion <https://doc.sagemath.org/html/en/reference/coercion/index.html>
_
Classes, Metaclasses <https://doc.sagemath.org/html/en/reference/misc/index.html#special-base-classes-decorators-etc>
_
FAQs
passagemath: Sage objects, elements, parents, categories, coercion, metaclasses
We found that passagemath-objects demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.