
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
Image processing service based on Sharp and Micro.
$ yarn install
$ yarn run start
We recommend to use Now together with Now CDN. See Now CDN documentation for setup.
To deploy this, run the following command.
$ now barnebys/bimp
Enter a secret and a no image url. Leave the env empty to disable signed url's and/or a no image url.
To specify the env upon deployment add the -e flag
$ now barnebys/bimp -e SECRET=MySecret -e NOT_FOUND_IMAGE_URL=https://someurl.com/image.jpg
https://<your-fqdn>/<url-or-path>?w=<width>&h=<height>&crop=<mode>
| Parameter | Function |
|---|---|
w | Image width |
h | Image height |
crop | Cropping mode |
extract | Extract a region of the image |
trim | Trim "boring" pixels from all edges |
pad | Add padding |
bg | Add a color to replace alpha or padded area |
s | Signed hash |
Resize image to width x height. When both height and width are use the image will be cropped to the specified size using center as default.
Crop the resized image to the exact specified size. Default is center.
Possible attributes are north, northeast, east, southeast, south,
southwest, west, northwest, center, centre, entropy and attention.
Other strategies for corpping are:
entropy: focus on the region with the highest Shannon entropy.
attention: focus on the region with the highest luminance frequency, colour saturation and presenece of skin tones..
Extract a region of the image using using left, top, width and height. Set left and top as offset and width and height for dimensions to extract.
extract=<left>,<top>,<width>,<height>
extract=0,0,500,200
Trim "boring" pixels from all edges using a tolerance (maximum of 99).
trim=10
Add padding to the image
pad=50
Replace alpha channel, or padded area, with a color.
bg=ffffff
bg=000000f1
FAQs
Barnebys Image Processor
The npm package bimp receives a total of 2 weekly downloads. As such, bimp popularity was classified as not popular.
We found that bimp demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.