
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
@stableness/shadowsocks-node
Advanced tools
Yet another shadowsocks client implementation in Node.js
npm install -g @stableness/shadowsocks-node
or
npx @stableness/shadowsocks-node
ss-node
-l, --local socks5://127.0.0.1:8080 or :8080 as socks5://0.0.0.0:8080
-r, --remote ss://password@example.com:4242
ss://method:password@example.com:4242
ss://base64url( method:password )@example.com:4242
ss://base64( method:password@example.com:4242 )
-k, --key overwrite the PASSWORD
-m, --method optional overwrite the method, default to chacha20-ietf-poly1305
-s, --subscribe path to local file or remote http page contains multiline addresses
-f, --refresh reload subscription address in seconds, default to 3600 (1 hour)
-q, --quiet suppress logging, silent mode
--enable_deprecated_cipher
--third_party_providers_use_at_your_own_risk
set local basic auth
-l socks5://username:password@127.0.0.1:8080
multi local proxies
-l socks5://127.0.0.1:8080 -l socks5://127.0.0.1:9090
multi remote addresses
-r ss://foo:4242 -r ss://bar:4343
multi subscription addresses
-s https://foo -s https://bar
accept deprecated stream ciphers (e.g. rc4 / rc4-md5 / aes-128-cfb etc.)
--enable_deprecated_cipher
free providers crawling from Internet USE AT YOUR OWN RISK
--third_party_providers_use_at_your_own_risk
(too long...)
--YOLO
FAQs
Yet another shadowsocks client implementation in Node.js
The npm package @stableness/shadowsocks-node receives a total of 5 weekly downloads. As such, @stableness/shadowsocks-node popularity was classified as not popular.
We found that @stableness/shadowsocks-node demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.