
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
catbox-redis
Advanced tools
Redis adapter for catbox
Lead Maintainer: Marcus Poehls
url - the Redis server URL (if url is provided, host, port, and socket are ignored)host - the Redis server hostname. Defaults to '127.0.0.1'.port - the Redis server port or unix domain socket path. Defaults to 6379.socket - the unix socket string to connect to (if socket is provided, host and port are ignored)password - the Redis authentication password when required.database - the Redis database.partition - this will store items under keys that start with this value. (Default: '')sentinels - an array of redis sentinel addresses to connect to.sentinelName - the name of the sentinel master. (Only needed when sentinels is specified)catbox-redis allows you to specify a custom Redis client. Using a custom client puts you in charge of lifecycle handling (client start/stop).
Requirements
client must be compatible with the ioredis APIclient must also expose the status property that needs to match ready when connectedclient is ready when client.status === 'ready' resolves to trueAll other options of catbox-redis are ignored when providing a custom client.
client - a custom Redis client instanceThe test suite expects:
/tmp/redis.sockSee .travis.yml
redis-server &
npm test
FAQs
Redis adapter for catbox
We found that catbox-redis demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.