Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
This guide provides dev teams with the technical information needed to integrate DeepRed into their applications
DeepRed is the monorepo for centralized Verizon AI service development. Personalization AI(PZAI) is an centralized personalization framework for building end to end large-scale search & recommender systems. The use cases developed on top of personalization AI can seamless integrate to Verizon personalization ecosystem, scale out to the Verizon AI infrastructure, and measurement framework in the production environment.
Personalization AI provides end-to-end support for:
PZAI plans to adopt a 90-day release cycle (major releases), currently working in progress. Please let us know if you encounter a bug by filing an issue. We appreciate all contributions. If you plan to contribute new features, bug fixes, or extensions to the core, please first open an issue and discuss the feature with us. Sending a PR without discussion might end up resulting in a rejected PR because we might be taking the core in a different direction than you might be aware of.
FAQs
vz recommender package
We found that vz-recommender demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.