
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@5app/memoize
Advanced tools
In computing, memoization or memoisation is an optimization technique used primarily to speed up computer programs by storing the results of expensive function calls and returning the cached result when the same inputs occur again. Memoization has also been used in other contexts (and for purposes other than speed gains), such as in simple mutually recursive descent parsing.[1] Although related to caching, memoization refers to a specific case of this optimization, distinguishing it from forms of caching such as buffering or page replacement. In the context of some logic programming languages, memoization is also known as tabling.[2]
https://en.wikipedia.org/wiki/Memoization
!Warning contrived example ahead...
import got from 'got'; // simple http requst library for the purpose of demonstration
import memoize from '@5app/memoize';
// Let's decorate the got function
const memoGot = memoize(got);
// Simultaneously open two connections...
const link = 'https://github.com';
Promise.all([memoGot(link), memoGot(link)];
// Will call...
// GET https://github.com
// ... but that's it, it wont call it again the second request will piggy back off the first.
memoize(handler, {...options})
option.useCache
(Boolean|Function): A truthy/fasly or a function to decide whether to use the cached record or not. Default true
option.staleInMs
Number: The number of milliseconds before the cache is deemed stale. Results will still be served from the cache whilst an attempt to refresh the cache is made separatly. Default 10000
ms.option.getKey
Function: A function to create a key based upon the input of the function being memoized. Default: a serialization of all the arguments.option.cache
Object: Instance of a Map like object to store the cache. Default new Map
options.cacheMaxSize
Number: The maximum number of entries to store in the cache. Default 1000
option.useCache
Whether to use cache this can be a Boolean value (useful to disable it when testing). Or a function e.g.
This snippet checks the cached value before deciding whether to use it...
import memoize from '@5app/memoize';
const memoGot = memoize(got, {
/**
* @param {object} cached_response - Cached Object
* @param {number} cached_response.timestamp - Timestamp when request resolved
* @param {string} cached_response.status - 'pending', 'fullfilled', 'rejected'
* @param {Promise<*>} cached_response.value - Promise of the request
* @returns {Boolean}
*/
useCache({timestamp, status}) {
// Set an expiry on the cache.
// 2xx, 3xx response last for a full minute before being reused
// 4xx, 5xx last only a second...
const age = value.statusCode >= 400 ? 1000 : 60000;
// Return true if the cache is un-expired, else false.
return timestamp > Date.now() - AGE;
}
}
// ...
// Use Memogot
// const req = memogot('link');
// ...
In testing to disable the memoize cache which can cause issues, use the MEMOIZE_DISABLE
environment variable, e.g.
MEMOIZE_DISABLE=1
When set to a truthy value the memoize cache will be circumvented.
FAQs
Memoize decorator
The npm package @5app/memoize receives a total of 92 weekly downloads. As such, @5app/memoize popularity was classified as not popular.
We found that @5app/memoize demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.