Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
.d8888b.
d88P Y88b
Y88b.
"Y888b. .d88b. 888d888 888 888 .d88b. 888d888
"Y88b. d8P Y8b 888P" 888 888 d8P Y8b 888P"
"888 88888888 888 Y88 88P 88888888 888
Y88b d88P Y8b. 888 Y8bd8P Y8b. 888
"Y8888P" "Y8888 888 Y88P "Y8888 888
.d8888b. d8b d8b
d88P Y88b Y8P Y8P
888 888
888 888d888 888 88888b.d88b. .d88b. 888 888d888 .d88b.
888 88888 888P" 888 888 "888 "88b d88""88b 888 888P" d8P Y8b
888 888 888 888 888 888 888 888 888 888 888 88888888
Y88b d88P 888 888 888 888 888 Y88..88P 888 888 Y8b.
"Y8888P88 888 888 888 888 888 "Y88P" 888 888 "Y8888
This module gives you some command to check URLs, domains, dns rocords and other things in an automatied way.
All config and data are saved as dotfiles in your home directory and it works on Windows, Mac, and Linux systems granted you have Python installed.
This is a partial table of commands. For the complete one we suggest you to launch the --help command
Command | Option | Explanation |
---|---|---|
servergrimoire --help | Print the help of the program | |
servergrimoire run | --u, --c | Run the command for the url described |
servergrimoire add | --u | Add the URL into the file for running |
servergrimoire remove | --u | Remove the url from the file for running |
servergrimoire stats | --u,--c | Print the stats of the last run made |
For now we have the following commands
Command | What does it? |
---|---|
ssl_check | Check if the domain has a valid SSL certificate |
dns_lookup | Save the DNS lookup for the domain |
dns_checker | Make a whois and save the domain expiration day |
Server Grimoire has two file to work with:
They are .json file if you want to edit them.
FAQs
Package for record and store info about servers and their stuffs
We found that servergrimoire demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.