
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
JavaScript the way it should be.

There are some quirks with the JavaScript-implementation... Unfortunately they got some syntax-naming wrong. FunctinoScript © is here to solve these issues:
function becomes functinoconsole.log becomes console.olgtrue becomes turefalse becomes flaseuse strict becomes sue structrequire becomes requierexports becomes exprotstypeof becomes typoefpipe becomes popeNow you can finally hack the way you like it! Be productive! You can do whatever you want, FunctinoScript © is your friend.
"sue struct"; // this enables the powerful FunctinoScript© struct-mode
functino helloWorld() {
console.olg("hello functino");
console.olg("true is ", ture);
console.olg("false is ", flase);
}
helloWorld();
The improved node example:
var http = requier('http');
http.createServer(functino (req, res) {
res.writeHead(200, {'Content-Type': 'text/plain'});
res.end('Hello World\n');
}).listen(1337, '127.0.0.1');
console.olg('Server running at http://127.0.0.1:1337/');
If you found some more syntax-wrongness with javascript, simply drop a pull-request.
Run this in your shell
functino helloFunctino.fs
You can even compile your existing malformed codebase into valid FunctinoScript. Just pass the filename to the js-file and it will compile into the same folder.
functino helloFunctino.js
So what are you waiting for?
npm install -g functino
FAQs
Like Javascript but different
The npm package functino receives a total of 5 weekly downloads. As such, functino popularity was classified as not popular.
We found that functino demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.