
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
Find a file or directory by walking up parent directories or down descendant directories
npm install find-up
/
└── Users
└── sindresorhus
├── unicorn.png
└── foo
└── bar
├── baz
└── example.js
example.js
import path from 'node:path';
import {pathExists} from 'path-exists';
import {findUp, findDown} from 'find-up';
console.log(await findUp('unicorn.png'));
//=> '/Users/sindresorhus/unicorn.png'
console.log(await findUp(['rainbow.png', 'unicorn.png']));
//=> '/Users/sindresorhus/unicorn.png'
console.log(await findUp(async directory => {
const hasUnicorn = await pathExists(path.join(directory, 'unicorn.png'));
return hasUnicorn && directory;
}, {type: 'directory'}));
//=> '/Users/sindresorhus'
// Find .git (could be a file or directory, common in submodules)
console.log(await findUp('.git', {type: 'both'}));
//=> '/Users/sindresorhus/.git'
Returns a Promise for either the path or undefined if it could not be found.
Returns a Promise for either the first path found (by respecting the order of names) or undefined if none could be found.
Returns a Promise for either an array of all paths found or an empty array if none could be found.
Note: You can limit the number of matches by setting the limit option.
Returns a Promise for either an array of all paths found (by respecting the order of names) or an empty array if none could be found.
Note: You can limit the number of matches by setting the limit option.
Returns a path or undefined if it could not be found.
Returns the first path found (by respecting the order of names) or undefined if none could be found.
Returns an array of all paths found or an empty array if none could be found.
Returns an array of all paths found (by respecting the order of names) or an empty array if none could be found.
Note: You can limit the number of matches by setting the limit option.
Find a file or directory by walking down descendant directories from cwd.
Returns a Promise for either the path or undefined if it could not be found.
import {findUp, findDown} from 'find-up';
// Find the nearest parent directory that contains a specific file
// in its direct children (useful for monorepo roots)
console.log(await findUp(async directory => {
return findDown('example.js', {cwd: directory, depth: 1});
}));
//=> '/Users/sindresorhus/foo'
Synchronous version of findDown.
Returns the path or undefined if it could not be found.
Type: string
The name of the file or directory to find. Can be an array of names to search for multiple files.
Type: Function
Called for each directory in the search. Return a path or findUpStop to stop the search. Useful if you want to match files with certain patterns, set of permissions, or other advanced use-cases.
Type: object
Type: URL | string
Default: process.cwd()
The directory to start from.
Type: string
Default: 'file'
Values: 'file' | 'directory' | 'both'
The type of path to match.
Type: boolean
Default: true
Allow symbolic links to match if they point to the chosen path type.
Only for findUp functions
Type: URL | string
Default: Root directory
A directory path where the search halts if no matches are found before reaching this point.
Only for findUpMultiple and findUpMultipleSync
Type: number
Default: Infinity
The maximum number of matches to return. Useful for limiting results when searching for multiple files.
A Symbol that can be returned by a matcher function to stop the search and cause findUp to immediately return undefined. Useful as a performance optimization in case the current working directory is deeply nested in the filesystem.
import path from 'node:path';
import {findUp, findUpStop} from 'find-up';
await findUp(directory => {
// Stop searching if we've reached a 'work' directory
if (path.basename(directory) === 'work') {
return findUpStop;
}
// Look for package.json in this directory
return 'package.json';
});
Type: object
Type: URL | string
Default: process.cwd()
The directory to start from.
Type: number
Default: 1
Maximum number of directory levels to traverse below cwd.
Type: string
Default: 'file'
Values: 'file' | 'directory' | 'both'
The type of path to match.
Type: boolean
Default: true
Allow symbolic links to match if they point to the chosen path type.
Type: string
Default: 'breadth'
Values: 'breadth' | 'depth'
Search strategy to use:
'breadth': Breadth-first search, finds shallower matches first.'depth': Depth-first search, fully explores each branch before moving to the next.require.resolve() but from a given pathThe locate-path package is similar to find-up as it also searches for files or directories by traversing up the directory tree. However, locate-path does not provide the convenience methods for matching files that find-up does.
The pkg-up package is designed specifically to find the closest package.json file in the directory tree. It is a more specialized tool compared to find-up, which can search for any file or directory.
findup-sync is similar to find-up but uses glob patterns for searching and is based on the micromatch library. It provides a synchronous API, unlike find-up which is promise-based and supports async/await.
FAQs
Find a file or directory by walking up parent directories
The npm package find-up receives a total of 204,953,242 weekly downloads. As such, find-up popularity was classified as popular.
We found that find-up demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.