
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
Searchable collection of bookmarks in a webpage
The collection presented at http://twolfson.github.io/bookmarks/ is my personal set distilled from Firefox.
bookmarks is hosted via GitHub pages meaning it is a set of static files. You can run a local server via a utility like serve.
# Install server if you haven't yet
npm install -g serve
# npm http GET https://registry.npmjs.org/serve
# npm http 200 https://registry.npmjs.org/serve
# ...
# Run serve
serve
# serving /home/todd/github/bookmarks on port 3000
Open http://localhost:3000/ in your browser and you should be presented with the webpage.
bookmarks.json is agnostic to being Firefox specific and it is planned that we support Pinboard in the future. The current structure is that from firefox-bookmarks' flatten method.
Object[] - Array of bookmarks
String - Name of the folderString - URL that was saved for the bookmarkString - Description for the linkNumber - Microseconds (milliseconds/1000) since Linux epoch that bookmark was addedNumber - Microseconds since Linux epoch that bookmark was last updatedWe provide utility functions to load your Firefox bookmarks.
# Copy latest bookmark backup to `bookmarks.orig.json`
npm run copy-firefox-bookmarks
# Flatten and beautify `bookmarks.orig.json` into `bookmarks.min.json` and `bookmarks.json`
npm run parse-bookmarks
Support this project and others by twolfson via gittip.
Copyright (c) 2013 Todd Wolfson
Licensed under the MIT license.
FAQs
Searchable collection of bookmarks in a webpage
The npm package bookmarks receives a total of 33 weekly downloads. As such, bookmarks popularity was classified as not popular.
We found that bookmarks demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.