Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
This package contains an OMF6 Resource Proxy for use with the VESNA Log-a-tec
testbed. Once installed, it registers a resource type cluster
with the
resource controller.
Each cluster
resource represents one cluster of VESNA sensor nodes. The
cluster
OMF resource replaces the usual node
OMF resource in that it
can be used to create application
resources. The applications used in this
way get information via environment on which cluster they are supposed to
operate.
The usual way to use this package is to use the normal omf_rc
resource
controller that comes in the omf_rc
package. config.yaml
should be
configured to load the omf_rc/resource_proxy/cluster
factory and create as
many cluster
resources as desired.
FAQs
Unknown package
We found that omf_rc_logatec demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.