
Security News
Another Round of TEA Protocol Spam Floods npm, But It’s Not a Worm
Recent coverage mislabels the latest TEA protocol spam as a worm. Here’s what’s actually happening.
This module provides a way to access single members of a zip file archive without downloading the full content from a remote web server. For this library to work, the web server hosting the archive needs to support the range header.
pip install remotezip
RemoteZip(url, ...)
To download the content, this library rely on the requests module. The constructor interface matches the function requests.get module.
False if the remote server doesn't support suffix range
(negative offset). Notice that this option will use one more HEAD request to fetch the content length.RemoteZip is a subclass of the python standard library class zipfile.ZipFile, so it supports all its read methods:
RemoteZip.close()RemoteZip.getinfo(name)RemoteZip.extract(member[, path[, pwd]])RemoteZip.extractall([path[, members[, pwd]]])RemoteZip.infolist()RemoteZip.namelist()RemoteZip.open(name[, mode[, pwd]])RemoteZip.printdir()RemoteZip.read(name[, pwd])RemoteZip.testzip()RemoteZip.filenameRemoteZip.debugRemoteZip.commentPlease look at the zipfile documentation for usage details.
NOTE:
extractall() and testzip() require to access the full content of the archive. If you need to use such methods, a full download of it would be probably more efficient.RemoteZip.open() now supports seek operations when reading archive members. However as the content is streamed and DEFLATE format doesn't support seek natively, any negative seek operation will result in a new remote request from the beginning of the member content. This is very inefficient, the recommandation is to use RemoteZip.extract() and then open and operate on the extracted file.Print all members part of the archive:
from remotezip import RemoteZip
with RemoteZip('http://.../myfile.zip') as zip:
for zip_info in zip.infolist():
print(zip_info.filename)
The following example will extract the file somefile.txt from the archive stored at the url http://.../myfile.zip.
from remotezip import RemoteZip
with RemoteZip('http://.../myfile.zip') as zip:
zip.extract('somefile.txt')
If you are trying to download a member from a zip archive hosted on S3 you can use the aws-requests-auth library for that as follow:
from aws_requests_auth.boto_utils import BotoAWSRequestsAuth
from hashlib import sha256
auth = BotoAWSRequestsAuth(
aws_host='s3-eu-west-1.amazonaws.com',
aws_region='eu-west-1',
aws_service='s3'
)
headers = {'x-amz-content-sha256': sha256('').hexdigest()}
url = "https://s3-eu-west-1.amazonaws.com/.../file.zip"
with RemoteZip(url, auth=auth, headers=headers) as z:
zip.extract('somefile.txt')
A simple command line tool is included in this distribution.
usage: remotezip [-h] [-l] [-d DIR] url [filename [filename ...]]
Unzip remote files
positional arguments:
url Url of the zip archive
filename File to extract
optional arguments:
-h, --help show this help message and exit
-l, --list List files in the archive
-d DIR, --dir DIR Extract directory, default current directory
$ remotezip -l "http://thematicmapping.org/downloads/TM_WORLD_BORDERS-0.3.zip"
Length DateTime Name
-------- ------------------- ------------------------
2962 2008-07-30 13:58:46 Readme.txt
24740 2008-07-30 12:16:46 TM_WORLD_BORDERS-0.3.dbf
145 2008-03-12 13:11:54 TM_WORLD_BORDERS-0.3.prj
6478464 2008-07-30 12:16:46 TM_WORLD_BORDERS-0.3.shp
2068 2008-07-30 12:16:46 TM_WORLD_BORDERS-0.3.shx
$ remotezip "http://thematicmapping.org/downloads/TM_WORLD_BORDERS-0.3.zip" Readme.txt
Extracting Readme.txt...
This module uses the zipfile.ZipFile class under the hood to decode the zip file format. The ZipFile class is initialized with a file like object that will perform transparently the remote queries.
The zip format is composed by the content of each compressed member followed by the central directory.
How many requests will this module perform to download a member?
ZipExtFile, each of them will result in a new request.There is a similar module available for python pyremotezip.
FAQs
Access zip file content hosted remotely without downloading the full file.
We found that remotezip demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Recent coverage mislabels the latest TEA protocol spam as a worm. Here’s what’s actually happening.

Security News
PyPI adds Trusted Publishing support for GitLab Self-Managed as adoption reaches 25% of uploads

Research
/Security News
A malicious Chrome extension posing as an Ethereum wallet steals seed phrases by encoding them into Sui transactions, enabling full wallet takeover.