
Research
Security News
Malicious npm Packages Use Telegram to Exfiltrate BullX Credentials
Socket uncovers an npm Trojan stealing crypto wallets and BullX credentials via obfuscated code and Telegram exfiltration.
pip install queue-az
The required connection string can be obtained from the Azure Portal, within the Storage account, "Access keys" tab
For convenience, you can set os.environ["BLOB_CONN_STR"]
. If you do, you can skip specifying it on every call.
E.g., create a .env
file:
BLOB_CONN_STR="<BLOB_CONN_STR>"
Then load it before importing
from dotenv import load_dotenv
load_dotenv()
import queue_az as qz
qz.client() # just works!
# single call
await qz.list.containers(conn_str=CONN_STR) # ain't necessary with a .env file
# multiple calls
async with qz.client() as client:
queues = await qz.list(client=client)
for q in queues:
print(await qz.msg.list(q, client=client))
queue_az
def client(...) -> QueueServiceClient
async def create(...)
async def delete(...)
async def list(...)
msg
async def send(...)
async def pop(...)
async def list(...)
FAQs
Async Python SDK for Azure Queue Storage
We found that queue-az demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket uncovers an npm Trojan stealing crypto wallets and BullX credentials via obfuscated code and Telegram exfiltration.
Research
Security News
Malicious npm packages posing as developer tools target macOS Cursor IDE users, stealing credentials and modifying files to gain persistent backdoor access.
Security News
AI-generated slop reports are making bug bounty triage harder, wasting maintainer time, and straining trust in vulnerability disclosure programs.