
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
@paypal/sdk-constants
Advanced tools
Constants for paypal sdk.
npm run setup./src and writing tests in ./testsnpm run buildnpm run build
npm run release to add a patch
npm run release:path, npm run release:minor, npm run release:majorThe 'stripe' package provides a comprehensive set of tools for integrating Stripe payment processing into applications. Similar to @paypal/sdk-constants, it offers constants and configurations for various payment-related functionalities, but it is specific to the Stripe ecosystem.
The 'braintree-web' package offers a JavaScript SDK for integrating Braintree payment processing. It includes constants and configurations similar to @paypal/sdk-constants, but it is tailored for Braintree's services.
The 'square' package provides tools for integrating Square payment processing. Like @paypal/sdk-constants, it includes constants and settings for various payment functionalities, but it is specific to Square's platform.
FAQs
Utilities.
The npm package @paypal/sdk-constants receives a total of 294,741 weekly downloads. As such, @paypal/sdk-constants popularity was classified as popular.
We found that @paypal/sdk-constants demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 26 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.