
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
@loaders.gl/loader-utils
Advanced tools
This module contains shared utilities for loaders.gl, a collection of framework-independent 3D and geospatial loaders (parsers).
For documentation please visit the website.
@loaders.gl/loader-utils includes helpers such as concatenateArrayBuffersAsync that operate
over ArrayBuffer, ArrayBufferView, and ArrayBufferLike inputs (including SharedArrayBuffer).
These utilities make it easy to normalize streamed binary data before handing it off to loaders.
Chunks backed by SharedArrayBuffer or typed array views are copied into standalone ArrayBuffer
instances so byte offsets and underlying storage quirks never corrupt concatenated output.
The 'buffer' package provides a way of handling binary data in Node.js. It offers similar functionalities for data conversion and manipulation, but it is more focused on low-level operations compared to the higher-level utilities provided by @loaders.gl/loader-utils.
The 'json5' package allows for parsing and stringifying JSON with more features than the standard JSON object. It offers similar JSON parsing capabilities but with additional features like comments and trailing commas, which are not supported by @loaders.gl/loader-utils.
The 'base64-js' package provides utilities for encoding and decoding Base64 data. It offers similar Base64 encoding functionalities but is more specialized and does not include the broader range of utilities found in @loaders.gl/loader-utils.
FAQs
Framework-independent loaders for 3D graphics formats
The npm package @loaders.gl/loader-utils receives a total of 666,525 weekly downloads. As such, @loaders.gl/loader-utils popularity was classified as popular.
We found that @loaders.gl/loader-utils demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 8 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.