
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
@appsignal/nodejs
Advanced tools
 
@appsignal/nodejs
The core AppSignal for Node.js library.
See also the mono repo README for more information.
First, sign up for an AppSignal account and run our automated install tool, which will install @appsignal/nodejs
and any relevant integrations to your project:
npx @appsignal/cli install
You can also skip the automated tool and add @appsignal/nodejs
to your package.json
on the command line with npm
/yarn
:
yarn add @appsignal/nodejs
npm install --save @appsignal/nodejs
Alternatively, you can manually add the @appsignal/nodejs
package to your package.json
. Then, run yarn install
/npm install
.
Installing the AppSignal for Node.js integration builds a native extension. In order to compile it, macOS users will need to install the Xcode Developer Tools. Linux users will need the dependencies outlined here. Windows is not supported.
You can then import and use the package in your bundle:
const { Appsignal } = require("@appsignal/nodejs");
const appsignal = new Appsignal({
active: true,
name: "<YOUR APPLICATION NAME>"
apiKey: "<YOUR API KEY>"
});
// ...all the rest of your code goes here!
In order to auto-instrument modules, the Appsignal module must be both required and initialized before any other package.
2.1.0
723b98d minor - Add rootSpan and setError helpers.
Errors added to child spans are ignored by the agent. Now the rootSpan is always accessible from the tracer object as well as setError. The setError function allows to track errors on demand and they will be always attached to the main current span, so they don't get ignored by the agent.
f0256d3 patch - Bug fix in custom timestamp calculation
1f182a4 patch - Deprecate the addError function on the Span interface. Instead use the Tracer's setError
function to set the error on the root span.
96df8a4 patch - Add sendError helper to Tracer object.
This new helper allows you to track an error separately from any other span inside the current context. Or use it to set up in your own error handling to report errors in a catch-statement if no performance monitoring is needed.
try {
// Do complex stuff
} catch (error) {
appsignal.tracer().sendError(error, span => {
span.setName("daily.task"); // Set a recognizable action name
span.set("user_id", user_id); // Set custom tags
});
}
patch - Update @appsignal/nodejs-ext dependency to 2.0.1.
FAQs
The AppSignal for Node.js library.
The npm package @appsignal/nodejs receives a total of 11,928 weekly downloads. As such, @appsignal/nodejs popularity was classified as popular.
We found that @appsignal/nodejs demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.