Sandworm

Sandworm

Follow
Follow
homeDocsSitenewslettermembers
Tag

Security

#security

More content

Read more stories on Hashnode


Articles with this tag

PHP & Composer Support Is Here! 🐘

Gabi DobocanGabi Dobocan
Sep 25, 20232 min read

We're excited to announce Sandworm is adding support for PHP via the Composer package manager. Composer has over 300,000 packages available, covering...

PHP & Composer Support Is Here! 🐘

🎡 Audit Your Workspaces With Sandworm v1.46.0

Gabi DobocanGabi Dobocan
Sep 1, 20235 min read

Today we're excited to bring you some highly anticipated additions to our Audit and Cloud products: monorepos, workspaces, and npm v1 lockfile...

🎡 Audit Your Workspaces With Sandworm v1.46.0

Security Alert: Don't `npm install https`

Gabi DobocanGabi Dobocan
Jun 15, 20233 min read

The Node.js https module is a built-in module that allows you to make secure HTTPS (Hypertext Transfer Protocol Secure) requests to servers. It...

Security Alert: Don't `npm install https`

The Npm Packages That Troll You

Gabi DobocanGabi Dobocan
May 3, 20233 min read

Npm install scripts are a powerful tool for developers who want to automate tasks related to installing and configuring their packages. They can be...

The Npm Packages That Troll You

Dissecting Npm Malware: Five Packages And Their Evil Install Scripts

Gabi DobocanGabi Dobocan
Apr 15, 20237 min read

Packages published on npm can declare pre and post-install hooks, which are scripts that run, well, pre or post-install. That is to say, when the npm...

Dissecting Npm Malware: Five Packages And Their Evil Install Scripts

One In Two New Npm Packages Is SEO Spam Right Now

Gabi DobocanGabi Dobocan
Mar 30, 20233 min read

More than half of all new packages that are currently (29 Mar 2023) being submitted to npm are SEO spam. That is - empty packages, with just a single...

One In Two New Npm Packages Is SEO Spam Right Now