
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@arcjet/analyze-wasm
Advanced tools
@arcjet/analyze-wasmArcjet helps developers protect their apps in just a few lines of code. Implement rate limiting, bot protection, email verification, and defense against common attacks.
This package provides WebAssembly bindings to Arcjet's local analysis engine.
This package provides logic in WebAssembly to locally analyze requests.
To load these binary files everywhere until something like
Import Bytes is available,
we settled on a technique that seems to work well everywhere.
This technique gives us compatibility with for example Next.js which right now
requires a special experimental asyncWebAssembly webpack configuration,
The file _virtual/arcjet_analyze_js_req.component.core.js contains the
WebAssembly inlined as a data: URL.
This is about 3 times smaller than using a Uint8Array (see
Better Binary Batter: Mixing Base64 and Uint8Array for more
info).
That URL is then turned into an ArrayBuffer and passed to
WebAssembly.compile.
The files here are generated.
They are wrapped up into @arcjet/analyze for use in
JavaScript,
in turn exposed in our core package
([arcjet][github-arcjet-arcjet])
and our SDKs (such as @arcjet/next).
This is an internal Arcjet package not designed for public use. See our Get started guide for how to use Arcjet in your application.
This package is ESM only. Install with npm in Node.js:
npm install @arcjet/analyze-wasm
Use @arcjet/analyze instead.
FAQs
WebAssembly bindings to Arcjet's local analysis engine
The npm package @arcjet/analyze-wasm receives a total of 42,232 weekly downloads. As such, @arcjet/analyze-wasm popularity was classified as popular.
We found that @arcjet/analyze-wasm demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.