
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
Try to downgrade the permissions of a process with root privileges and block access if it fails
Try to downgrade the permissions of a process with root privileges and block access if it fails

$ npm install root-check
import rootCheck from 'root-check';
rootCheck();
See the sudo-block API.
The sudo-block package prevents a process from running with sudo privileges. Unlike root-check, which downgrades the process from root to a regular user, sudo-block simply exits the process if it detects that it is running with sudo privileges.
The is-root package checks if the process is running as root. It does not downgrade the process but can be used to conditionally execute code based on whether the process has root privileges. This is different from root-check, which actively downgrades the process.
FAQs
Try to downgrade the permissions of a process with root privileges and block access if it fails
The npm package root-check receives a total of 281,235 weekly downloads. As such, root-check popularity was classified as popular.
We found that root-check demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.