
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@phaserjs/streamdown-lite
Advanced tools
A drop-in replacement for react-markdown, designed for AI-powered streaming.
A lightweight drop-in replacement for react-markdown, designed for AI-powered streaming with code highlighting.
Formatting Markdown is easy, but when you tokenize and stream it, new challenges arise. Streamdown is built specifically to handle the unique requirements of streaming Markdown content from AI models, providing seamless formatting even with incomplete or unterminated Markdown blocks.
Streamdown powers the AI Elements Response component but can be installed as a standalone package for your own streaming needs.
react-markdownnpm i @phaserjs/streamdown-lite
Then, update your Tailwind globals.css to include the following.
@source "../node_modules/@phaserjs/streamdown-lite/dist/index.js";
Make sure the path matches the location of the node_modules folder in your project. This will ensure that the Streamdown styles are applied to your project.
import { Streamdown } from '@phaserjs/streamdown-lite';
export default function Page() {
const markdown = "# Hello World\n\nThis is **streaming** markdown!";
return <Streamdown>{markdown}</Streamdown>;
}
'use client';
import { useChat } from '@ai-sdk/react';
import { useState } from 'react';
import { Streamdown } from '@phaserjs/streamdown-lite';
export default function Page() {
const { messages, sendMessage, status } = useChat();
const [input, setInput] = useState('');
return (
<>
{messages.map(message => (
<div key={message.id}>
{message.parts.filter(part => part.type === 'text').map((part, index) => (
<Streamdown key={index}>{part.text}</Streamdown>
))}
</div>
))}
<form
onSubmit={e => {
e.preventDefault();
if (input.trim()) {
sendMessage({ text: input });
setInput('');
}
}}
>
<input
value={input}
onChange={e => setInput(e.target.value)}
disabled={status !== 'ready'}
placeholder="Say something..."
/>
<button type="submit" disabled={status !== 'ready'}>
Submit
</button>
</form>
</>
);
}
Streamdown accepts all the same props as react-markdown, plus additional streaming-specific options:
| Prop | Type | Default | Description |
|---|---|---|---|
children | string | - | The Markdown content to render |
parseIncompleteMarkdown | boolean | true | Parse and style unterminated Markdown blocks |
className | string | - | CSS class for the container |
components | object | - | Custom component overrides |
remarkPlugins | array | [remarkGfm] | Remark plugins to use |
rehypePlugins | array | [rehypeKatex] | Rehype plugins to use |
allowedImagePrefixes | array | ['*'] | Allowed image URL prefixes |
allowedLinkPrefixes | array | ['*'] | Allowed link URL prefixes |
defaultOrigin | string | - | Default origin to use for relative URLs in links and images |
Note: Streamdown-lite also accepts all props from react-markdown through inheritance.
Streamdown-lite is built as a monorepo with:
packages/streamdown-lite - The core React component libraryapps/website - Documentation and demo site# Install dependencies
pnpm install
# Build the streamdown-lite package
pnpm --filter streamdown-lite build
# Run development server
pnpm dev
# Run tests
pnpm test
# Build packages
pnpm build
Contributions are welcome! Please feel free to submit a Pull Request.
FAQs
A drop-in replacement for react-markdown, designed for AI-powered streaming.
We found that @phaserjs/streamdown-lite demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.