
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
A hapi plugin integrating Objection ORM
Lead Maintainer - Devin Ivy
See also the API Reference
Schwifty is used to define Joi-compatible models and knex connections for use with Objection ORM. Those models then become available within your hapi server where it is most convenient. It has been tailored to multi-plugin deployments, where each plugin may set clear boundaries in defining its own models, knex database connections, and migrations. It's safe to register schwifty multiple times, wherever you'd like to use it, as it protects against model name collisions and other ambiguous configurations.
Note
Schwifty is intended for use with hapi v17+, joi v16+, Objection v1 and v2, knex v0.16+, and nodejs v8+. If you're using an older version of knex or joi, check out schwifty v4.
// First, ensure your project includes knex, objection, and sqlite3
// To get started you might run,
// npm install --save schwifty @hapi/hapi joi knex objection sqlite3
'use strict';
const Hapi = require('@hapi/hapi');
const Joi = require('joi');
const Schwifty = require('schwifty');
(async () => {
const server = Hapi.server({ port: 3000 });
server.route({
method: 'get',
path: '/dogs/{id}',
handler: async (request) => {
const { Dog } = request.models();
return await Dog.query().findById(request.params.id);
}
});
await server.register({
plugin: Schwifty,
options: {
knex: {
client: 'sqlite3',
useNullAsDefault: true,
connection: {
filename: ':memory:'
}
}
}
});
// Register a model with schwifty...
server.schwifty(
class Dog extends Schwifty.Model {
static get tableName() {
return 'Dog';
}
static get joiSchema() {
return Joi.object({
id: Joi.number(),
name: Joi.string()
});
}
}
);
await server.initialize();
// ... then make a table ...
const knex = server.knex();
await knex.schema.createTable('Dog', (table) => {
table.increments('id').primary();
table.string('name');
});
// ... then add some records ...
const { Dog } = server.models();
await Promise.all([
Dog.query().insert({ name: 'Guinness' }),
Dog.query().insert({ name: 'Sully' }),
Dog.query().insert({ name: 'Ren' })
]);
// ... then start the server!
await server.start();
console.log(`Now, go find some dogs at ${server.info.uri}`);
})();
FAQs
A hapi plugin integrating Objection ORM
The npm package schwifty receives a total of 98 weekly downloads. As such, schwifty popularity was classified as not popular.
We found that schwifty demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.