
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
taskcluster-base
Advanced tools
You should install any libraries this library includes directly into your project if you wish to use them.
A collection of common modules used many taskcluster components.
Most of the modules in this base collection can be instantiated by providing a JSON dictionary with configuration and parameters.
There is no need (and in fact it should be impossible) to manually publish a new version of this package.
Upon pushing an appropriately tagged version to Github, Travis will pick this up and deploy a new version
for you, assuming the tests pass. New versions should be created with npm version rather than by
manually editing package.json and tags should be pushed to Github.
We're sticking to semver as much as possible in Taskcluster, so please keep that in mind as you update versions and release packages.
camelBack notation for all public identifiersCamelCase notation for class names/** Documentation comments */There are no tests in this module other than assuring that everything can
be imported. Run with npm test as per usual.
We publish metadata for consumption by auto-generated clients and docs.
API References should be published to
references.taskcluster.net/<component>/v1, where <component> is a
taskcluster component, such as queue, scheduler, etc.
Schemas should be published to schemas.taskcluster.net/<component>/v1,
where <component> is the name of a taskcluster component, as above.
Please, do not publish metadata from staging area deployments or test setups, etc. If you want to maintain deploy a different version of a component independently please make sure to choose a unique component name or publish the application metadata to another location.
FAQs
Common modules for taskcluster components
The npm package taskcluster-base receives a total of 219 weekly downloads. As such, taskcluster-base popularity was classified as not popular.
We found that taskcluster-base demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.