
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@arcjet/stable-hash
Advanced tools
@arcjet/stable-hashArcjet stable hashing utility.
This is an internal utility to help us create stable hashes. It’s super minimal and matches similar internal code in other languages. This exists to make sure things work the same across languages.
This is an internal Arcjet package not designed for public use. See our Get started guide for how to use Arcjet in your application.
This package is ESM only. Install with npm in Node.js:
npm install @arcjet/stable-hash
import * as hasher from "@arcjet/stable-hash";
const id = await hasher.hash(
hasher.string("type", "EMAIL"),
hasher.uint32("version", 0),
hasher.string("mode", "LIVE"),
hasher.stringSliceOrdered("allow", []),
hasher.stringSliceOrdered("deny", []),
);
console.log(id);
// => 49573b7df8d854c2cd5d8a755a4c03aff4014493a41b963490861a279ad675b2
Apache License, Version 2.0 © Arcjet Labs, Inc.
Derivative work based on feross/buffer licensed under
MIT © Feross Aboukhadijeh and contributors.
Our work picks its internal hex encoding logic adjusted for our use.
FAQs
Arcjet stable hashing utility
The npm package @arcjet/stable-hash receives a total of 0 weekly downloads. As such, @arcjet/stable-hash popularity was classified as not popular.
We found that @arcjet/stable-hash demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.