
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
A framework for quickly and easily setting up and deploying Actions on Google projects.
Features include:
Planned features:
For a skeleton project including full boilerplate and example code, look here: Kiai Skeleton
$ npm add kiai
Create an ./index.js with the following code:
const Kiai = require('kiai').default;
const flows = {
main: require('./flows/main'),
};
const app = new Kiai({ flows });
app.addPlatform(Kiai.PLATFORMS.DIALOGFLOW);
app.setFramework(Kiai.FRAMEWORKS.EXPRESS);
main_welcome and add the WELCOME event to it.$ ngrok http 3000 to create a publicly accessible tunnel to your local machine on the default port of 3000, and paste the https URL it outputs in the Fullfilment section of your Dialogflow project, adding the /dialogflow endpoint../flows/main.js file and put in the following:module.exports = {
welcome(conv) {
conv.say('Hello world!').end();
},
};
index.jsFAQs
Kiai Voice Action Framework
We found that kiai demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.