
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
m3u8stream
Advanced tools
Reads segments from a m3u8 playlist or DASH MPD file into a consumable stream.
const fs = require('fs');
const m3u8stream = require('m3u8stream')
m3u8stream('http://somesite.com/link/to/the/playlist.m3u8')
.pipe(fs.createWriteStream('videofile.mp4'));
Creates a readable stream of binary media data. options can have the following
begin - Where to begin playing the video. Accepts an absolute unix timestamp or date and a relative time in the formats 1:23:45.123 and 1m2s.liveBuffer - How much buffer in milliseconds to have for live streams. Default is 20000.chunkReadahead - How many chunks to preload ahead. Default is 3.highWaterMark - How much of the download to buffer into the stream. See node's docs for more. Note that the actual amount buffered can be higher since each chunk request maintains its own buffer.requestOptions - Any options you want to pass to miniget, such as headers.parser - Either "m3u8" or "dash-mpd". Defaults to guessing based on the playlist url ending in .m3u8 or .mpd.id - For playlist containing multiple media options. If not given, the first representation will be picked.If called, stops requesting segments, and refreshing the playlist.
Object - Current segment with the following fields,
number - numnumber - sizenumber - durationstring - urlnumber - Total number of segments.number - Bytes downloaded up to this point.For static non-live playlists, emitted each time a segment has finished downloading. Since total download size is unknown until all segment endpoints are hit, progress is calculated based on how many segments are available.
All miniget events are forwarded and can be listened to from the returned stream.
Converts human friendly time to milliseconds. Supports the format
00:00:00.000 for hours, minutes, seconds, and milliseconds respectively.
And 0ms, 0s, 0m, 0h, and together 1m1s.
time - A string (or number) giving the user-readable input dataCurrently, it does not support encrypted media segments. This is because the sites where this was tested on and intended for, YouTube and Twitch, don't use it.
This does not parse master playlists, only media playlists. If you want to parse a master playlist to get links to media playlists, you can try the m3u8 module.
npm install m3u8stream
Tests are written with mocha
npm test
hls.js is a JavaScript library that allows you to play HLS streams in browsers that do not support HLS natively. It is primarily used for client-side playback in web applications, whereas m3u8stream is used for server-side streaming and downloading.
fluent-ffmpeg is a Node.js library for working with FFmpeg, a powerful multimedia framework. It can be used to download and process media streams, including HLS streams. However, it requires FFmpeg to be installed and is more complex to use compared to m3u8stream.
FAQs
Reads segments from a m3u8 or dash playlist into a consumable stream.
The npm package m3u8stream receives a total of 217,608 weekly downloads. As such, m3u8stream popularity was classified as popular.
We found that m3u8stream demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.