Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Specklia is a cloud-hosted geospatial point cloud database designed for satellite altimetry data, produced by Earthwave Ltd. This package is the open-source Python Client for Specklia. It is intended for use by Academics within automated workflows and Jupyter Notebooks. Note that in order to use Specklia, you must first generate an API key.
When using Earth Observation data, Academics are often presented with deeply nested folder structures containing headers that need to be manually parsed and files that contain large quantites of data not relevant to the current study. Specklia solves this problem by allowing users to request only the data within their desired study region, time period, and other filter criteria, and have it delivered right into their python workspace as a GeoDataFrame, without losing any of the headers and traceability information that standard product files provide.
Specklia was produced using funding from the European Space Agency, and originally designed to host the Cryo-TEMPO EOLIS Products, which are derived from CryoSat-2 data. More information can be found at Specklia's home page.
If you're interested in influencing Specklia's development, using it in ways that are not immediately enabled by the python client, or you have other support queries, please contact support@earthwave.co.uk.
FAQs
Python client for Specklia, a geospatial point cloud database by Earthwave.
We found that specklia demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.