
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
Get the ID of the process that uses a certain port
npm install pid-port
import {portToPid} from 'pid-port';
try {
// Only checks localhost by default
console.log(await portToPid(8080));
//=> 1337
// Same as above
console.log(await portToPid({port: 8080}));
//=> 1337
const pids = await portToPid([8080, 22]);
console.log(pids.get(8080));
//=> 1337
console.log(pids.get(22));
//=> 12345
// Specific host
console.log(await portToPid({port: 8080, host: '127.0.0.1'}));
//=> 1337
// Check all interfaces (use with caution)
console.log(await portToPid({port: 8080, host: '*'}));
//=> 1337
} catch (error) {
console.log(error);
//=> 'Could not find a process that uses port `8080` on localhost'
}
Get the process ID for a port.
Returns a Promise<number | undefined> (integer) with the process ID.
[!NOTE] By default, only checks localhost (
127.0.0.1and::1). Use{host: '*'}to check all interfaces if needed.
Linux privilege requirements: On Linux systems, process ID information may not be visible to non-privileged users. If a port is found but no PID is returned, the package will attempt to use lsof as a fallback (requires lsof to be installed).
Type: number | {port: number, host?: string}
Either a port number directly, or an options object with:
port (number): The port to look uphost (string, optional): The host to filter by. Use '*', '0.0.0.0', or '::' for all interfaces. Use 'localhost' for explicit localhost filtering.Get the process IDs for multiple ports.
Returns a Promise<Map<number, number>> (integer) with the port as key and the process ID as value.
import {portToPid} from 'pid-port';
try {
const pids = await portToPid([8080, 22]);
console.log(pids.get(8080));
//=> 1337
console.log(pids.get(22));
//=> 12345
} catch (error) {
console.log(error);
//=> 'Could not find a process that uses port `8080`'
}
Type: number[] (integer)
The ports to look up.
Get the ports for a process ID.
Returns a Promise<Set<number>> with the ports.
import {pidToPorts} from 'pid-port';
try {
const ports = await pidToPorts(1337);
//=> Set { 8080, 22 }
} catch (error) {
console.log(error);
}
Type: number
The process ID to look up.
Get the ports for multiple process IDs.
Returns a Promise<Map<number, Set<number>>> with the process ID as the key and the ports as value.
import {pidToPorts} from 'pid-port';
try {
const ports = await pidToPorts([1337, 12345]);
//=> Map { 1337 => Set { 8080, 22 }, 12345 => Set { 3000 } }
} catch (error) {
console.log(error);
}
Type: number[]
The process IDs to look up.
Get all ports with their process ID, optionally filtered by host.
Returns a Promise<Map<number, number>> (integer) with the port as key and the process ID as value.
[!NOTE] By default, only checks localhost (
127.0.0.1and::1). Use{host: '*'}to check all interfaces if needed.
import {allPortsWithPid} from 'pid-port';
try {
// Only localhost ports
const localhost = await allPortsWithPid();
//=> Map { 8080 => 1337, 22 => 12345 }
// Specific host
const filtered = await allPortsWithPid({host: '127.0.0.1'});
//=> Map { 8080 => 1337, 22 => 12345 }
// All interfaces (use with caution)
const all = await allPortsWithPid({host: '*'});
//=> Map { 8080 => 1337, 22 => 12345, 3000 => 14311 }
} catch (error) {
console.log(error);
}
Type: object (optional)
Type: string (optional)
The host to filter by. Use '*', '0.0.0.0', or '::' for all interfaces.
Get all process bindings for a specific port.
Returns a Promise<Array<{host: string; pid: number}>> with detailed binding information.
[!NOTE] By default, only checks localhost (
127.0.0.1and::1). Use{host: '*'}to check all interfaces if needed.
import {portBindings} from 'pid-port';
try {
// Only localhost bindings
const bindings = await portBindings(8080);
//=> [{host: '127.0.0.1', pid: 1337}]
// All interfaces (use with caution)
const allBindings = await portBindings(8080, {host: '*'});
//=> [
// {host: '127.0.0.1', pid: 1337},
// {host: '192.168.1.1', pid: 5678}
// ]
} catch (error) {
console.log(error);
}
Type: number (integer)
The port to look up.
Type: object (optional)
Type: string (optional)
The host to filter by. Use '*', '0.0.0.0', or '::' for all interfaces.
FAQs
Get the ID of the process that uses a certain port
The npm package pid-port receives a total of 235,696 weekly downloads. As such, pid-port popularity was classified as popular.
We found that pid-port demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.