
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
This is a work in progress. The library is usable, however it is still evolving and may have some breaking changes in the future. These will most likely be minor, in addition to extending functionality.
In the future this library will be a wrapper around the new implementation of MAM https://github.com/iotaledger/entangled/tree/develop/mam
It is possible to publish transactions to the Tangle that contain only messages, with no value. This introduces many possibilities for data integrity and communication, but comes with the caveat that message-only signatures are not checked. What we introduce is a method of symmetric-key encrypted, signed data that takes advantage of merkle-tree winternitz signatures for extended public key usability, that can be found trivially by those who know to look for it.
This is wrapper library for the WASM/ASM.js output of the IOTA Bindings repository. For a more in depth look at how Masked Authenticated Messaging works please check out the Overview
Add the package to your project with:
npm install @iota/mam
or
yarn add @iota/mam
After adding the package it will provide access to the functions described below. To import the module simple use one of the following methods, depending on which version of JavaScript you are using.
const Mam = require('@iota/mam');
Mam.init(...);
or
import * as Mam from '@iota/mam';
Mam.init(...);
or in the browser using
<script src="./lib/mam.web.min.js"></script>
<script>
Mam.init(...)
</script>
For a simple user experience you are advised to call the init() function to enable to tracking of state in your channels. When calling init() you should pass in the provider which is the address of an IRI node. This will provide access to some extra functionality including attaching, fetching and subscribing.
initThis initialises the state. This will return a state object that tracks the progress of your channel and channels you are following
Mam.init(settings, seed, security)
Object or String Configuration object or network provider URL.
Configuration object:
String Network provider URL.Function function to override default attachToTangle to use another Node to do the PoW or use a PoW service.String Optional tryte-encoded seed. Null value generates a random seedInteger Optional security of the keys used. Null value defaults to 2changeModeThis takes the state object and changes the default channel mode from public to the specified mode and sidekey. There are only three possible modes: public, private, & restricted. If you fail to pass one of these modes it will default to public. This will return a state object that tracks the progress of your channel and channels you are following
Mam.changeMode(state, mode, sidekey)
Object Initialised IOTA library with a provider set.String Intended channel mode. Can be only: public, private or restrictedString Tryte-encoded encryption key, 81 trytes long. Required for restricted modegetRootThis method will return the root for the supplied mam state.
Mam.getRoot(state)
Object Initialised IOTA library with a provider set.createCreates a MAM message payload from a state object, tryte-encoded message and an optional side key. Returns an updated state and the payload for sending.
Mam.create(state, message)
Object Initialised IOTA library with a provider set.String Tryte-encoded payload to be encrypted. Tryte-encoded payload can be generated by calling asciiToTrytes from the @iota/converter and passing a stringified JSON objectObject Updated state object to be used with future actions.String Tryte-encoded payload.String Tryte-encoded root of the payload.String Tryte-encoded address used as an location to attach the payload.decodeEnables a user to decode a payload
Mam.decode(payload, sideKey, root)
String Tryte-encoded payload.String Tryte-encoded encryption key. Null value falls back to default keyString Tryte-encoded string used as the address to attach the payload.Object Updated state object to be used with future actions.String Tryte-encoded payload.String Tryte-encoded root used as an address to attach the payload.subscribeThis method will add a subscription to your state object using the provided channel details.
Mam.subscribe(state, channelRoot, channelMode, channelKey)
Object Initialised IOTA library with a provider set.String The root of the channel to subscribe to.String Optional, can one of public, private or restricted Null value falls back to publicString Optional, The key of the channel to subscribe to.listenListen to a channel for new messages.
Mam.listen(channel, callback)
Object The channel object to listen to.String Callback called when new messages arrive.Nothing
attach - asyncAttaches a payload to the Tangle.
await Mam.attach(payload, address, depth, minWeightMagnitude, tag)
String Tryte-encoded payload to be attached to the Tangle.String Tryte-encoded string returned from the Mam.create() function.number Optional depth at which Random Walk starts. A value of 3 is typically used by wallets, meaning that RW starts 3 milestones back. Null value will set depth to 3number Optional minimum number of trailing zeros in transaction hash. This is used by attachToTangle function to search for a valid nonce. Currently is 14 on mainnet & spamnnet and 9 on most other devnets. Null value will set minWeightMagnitude to 9String Optional tag of 0-27 trytes. Null value will set tag to empty stringArray Transaction objects that have been attached to the network.fetch - asyncFetches the channel sequentially from a known root and optional sidekey. This call can be used in two ways: Without a callback will cause the function to read the entire channel before returning. With a callback the application will return data through the callback and finally the nextroot when finished.
await Mam.fetch(root, mode, sidekey, callback, limit)
String Tryte-encoded string used as the entry point to a channel. NOT the address!String Channel mode. Can one of public, private or restricted Null value falls back to publicString Tryte-encoded encryption key. Null value falls back to default keyFunction Optional callback. Null value will cause the function to push payload into the messages array.Number Optional limits the number of items returned, defaults to all.String Tryte-encoded string pointing to the next root.Array Array of Tryte-encoded messages from the channel.fetchSingle - asyncFetches a single message from a known root and optional sidekey.
await Mam.fetchSingle(root, mode, sidekey)
String Tryte-encoded string used as the entry point to a channel. NOT the address!String Channel mode. Can one of public, private or restricted Null value falls back to publicString Tryte-encoded encryption key. Null value falls back to default keyString Tryte-encoded string pointing to the next root.String Tryte-encoded messages from the channel.Compiled libs are included in the repository. Compiling the Rust bindings can require some complex environmental setup to get to work, so if you are unfamiliar just stick to the compiled files.
This repo provides wrappers for both Browser and Node environments. The build script discriminates between a WASM.js and ASM.js build methods and returns files that are includable in your project.
The below commands will build a file called mam.client.js in the lib/ directory. You can then include the pacakge in your code using require/import.
// Install dependencies
yarn
// Build a development version lib/mam.client.js
yarn build-node-dev
// Build a production/minified version lib/mam.client.min.js
yarn build-node-prod
The below commands will build a file called mam.web.js in the lib/ directory. You can then include the package in your code using <script src="">
// Install dependencies
yarn
// Build a development version lib/mam.web.js
yarn build-web-dev
// Build a production/minified version lib/mam.web.min.js
yarn build-web-prod
To build all the libraries just run:
yarn dist
FAQs
Masked Authentication Messaging wrapper for Javascript (Browser and Node)
We found that @iota/mam demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.