Attackers Repurposing existing Python-based Malware for Distribution on NPM

This page summarizes the projects mentioned and recommended in the original post on /r/javascript

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
WorkOS - The modern identity platform for B2B SaaS
The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.
workos.com
featured
  • birdcage

    Cross-platform embeddable sandboxing

  • We've open sourced our sandbox, which limits access to network/disk/etc. during package installation. In this way, nasty install scripts won't have the opportunity to ship your credentials/SSH keys off to a remote sever.

  • cli

    Command line interface for the Phylum API (by phylum-dev)

  • This is bundled with our CLI tool today (which is also open source) and allows you to install packages with phylum npm install . We currently support npm, yarn and pip and are planning on rolling out further support for other ecosystems in coming months.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • Rust Malware Staged on Crates.io

    3 projects | news.ycombinator.com | 25 Aug 2023
  • Ransomware being published to PyPI in ongoing campaign

    2 projects | /r/Python | 9 Dec 2022
  • Attackers are hiding malware in minified packages distributed to NPM

    4 projects | /r/javascript | 30 Mar 2023
  • A Study of Malicious Code in PyPI Ecosystem

    4 projects | news.ycombinator.com | 8 Sep 2023
  • Can rustc generate identical binaries, with the same hash, from the same souce code?

    5 projects | /r/rust | 25 Jun 2023