Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Provides all the functionality of the stravalib package and extends it using web scraping.
In order to log into the website, the WebClient
class either needs an email and password, or the
JWT of an existing session. Strava stores this JWT
in the strava_remember_token
cookie.
After the client has logged in, a JWT for the current session can be accessed via the WebClient
's
jwt
property. Storing this JWT (and the access_token
from stravalib
) allows for resuming the
session without having to log in again. This can avoid rate limits and lockouts.
Example:
from stravaweblib import WebClient
# Log in (requires API token and email/password for the site)
client = WebClient(access_token=OAUTH_TOKEN, email=EMAIL, password=PASSWORD)
# Store the current session's information
jwt = client.jwt
access_token = client.access_token
# Create a new client that continues to use the previous web session
client = WebClient(access_token=access_token, jwt=jwt)
Download activity files as GPX, TCX, or the original format they were uploaded in.
from stravaweblib import WebClient, DataFormat
# Log in (requires API token and email/password for the site)
client = WebClient(access_token=OAUTH_TOKEN, email=EMAIL, password=PASSWORD)
# Get the first activity id (uses the normal stravalib API)
activities = client.get_activities()
activity_id = activities.next().id
# Get the filename and data stream for the activity data
data = client.get_activity_data(activity_id, fmt=DataFormat.ORIGINAL)
# Save the activity data to disk using the server-provided filename
with open(data.filename, 'wb') as f:
f.writelines(data.content)
Delete activities from the site. Note that this was previously possible via the API, but the endpoint has been removed as of 2017-01-17.
from stravaweblib import WebClient
# Log in (requires API token and email/password for the site)
client = WebClient(access_token=OAUTH_TOKEN, email=EMAIL, password=PASSWORD)
# Get the first activity id (uses the normal stravalib API)
activities = client.get_activities()
activity_id = activities.next().id
# Delete the activity
client.delete_activity(activity_id)
Retrieve all components added to bikes. Can optionally only show components active at a certain date.
from stravaweblib import WebClient
from datetime import datetime
# Log in (requires API token and email/password for the site)
client = WebClient(access_token=OAUTH_TOKEN, email=EMAIL, password=PASSWORD)
# Get a list of bikes the current user owns
athlete = client.get_athlete()
bikes = athlete.bikes
# Get the id of the first bike
bike_id = bikes.next().id
# Get all components of the first bike (past and present)
client.get_bike_components(bike_id)
# Get the current components on the first bike
client.get_bike_components(bike_id, on_date=datetime.now())
Download route files as GPX or TCX.
from stravaweblib import WebClient, DataFormat
# Log in (requires API token and email/password for the site)
client = WebClient(access_token=OAUTH_TOKEN, email=EMAIL, password=PASSWORD)
# Get the first route id (uses the normal stravalib API)
routes = client.get_routes()
route_id = routes.next().id
# Get the filename and data stream for the activity data
data = client.get_route_data(route_id, fmt=DataFormat.GPX)
# Save the activity data to disk using the server-provided filename
with open(data.filename, 'wb') as f:
f.writelines(data.content)
Licensed under the Mozilla Public License, version 2.0
FAQs
Extends the Strava v3 API using web scraping
We found that stravaweblib demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.