
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
@babel/plugin-syntax-dynamic-import
Advanced tools
Allow parsing of import()
See our website @babel/plugin-syntax-dynamic-import for more information.
Using npm:
npm install --save-dev @babel/plugin-syntax-dynamic-import
or using yarn:
yarn add @babel/plugin-syntax-dynamic-import --dev
Provides a React component-centric way to dynamically load components. It's more specific to React and offers a higher-level abstraction compared to @babel/plugin-syntax-dynamic-import, which is more low-level and syntax-focused.
Another React-specific library for dynamically loading components with promises. It offers a similar functionality to @loadable/component but was more popular before React.lazy and Suspense were introduced. Compared to @babel/plugin-syntax-dynamic-import, react-loadable provides a more integrated solution for React applications.
FAQs
Allow parsing of import()
The npm package @babel/plugin-syntax-dynamic-import receives a total of 14,271,258 weekly downloads. As such, @babel/plugin-syntax-dynamic-import popularity was classified as popular.
We found that @babel/plugin-syntax-dynamic-import demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.