
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
@badaimweeb/js-protov2d
Advanced tools
⚠️ This package is still in development, but should be usable. Use at your own risk, and please report any bugs you find.
ProtoV2d is a variant of ProtoV2 protocol, removing libp2p and instead only uses WebSocket to communicate. This results in not being able to seamlessly move the servers, but is much more lightweight and easier to use.
This package will expose a quantum-resistant encrypted tunnel, even when using unsecured WebSocket connections, and can be reconnectable even when using different client IP addresses.
This package works best when used with DTSocket.
This package relies heavily on WebCrypto, and it will not available in non-secure contexts. If you want to use this in that case, please add polyfills for WebCrypto.
You can polyfill WebCrypto by using @peculiar/webcrypto (crypto.subtle = webcryptoPolyfill). Make sure to also polyfill node.js crypto (browserify version).
Install:
npm install @badaimweeb/js-protov2d
Preshared key generation:
import { keyGeneration } from "@badaimweeb/js-protov2d";
let { privateKey, publicKey, publicKeyHash } = await keyGeneration();
// Note: you should share public key hash instead of full public key since public key is well over 6KB
Server usage (using internal WebSocket server):
import { Server } from "@badaimweeb/js-protov2d";
let server = new Server({
port: 0, // 0 = random TCP port
privateKey,
publicKey
});
let port: number = server.port;
server.on("connection", session => {
session.on("data", (QoS, data) => {
// QoS 0: send once
// QoS 1: send until acknowledged
// handle data here (data is Uint8Array)
});
// send data
session.send(QoS, data);
});
Server usage (using internal WebSocket server handling external HTTP(S) server) (also works with Express):
import { createServer as createHTTPServer } from "http";
let httpServer = createHTTPServer();
httpServer.listen(0);
let server = new Server({
server: httpServer,
privateKey,
publicKey
});
Client usage:
import { connect } from "@badaimweeb/js-protov2d";
// If you have public key:
let client = await connect({
url: `ws://localhost:${port}`,
publicKeys: [{
type: "key",
value: publicKey
}]
});
// or public key hash:
let client = await connect({
url: `ws://localhost:${port}`,
publicKeys: [{
type: "hash",
value: publicKeyHash
}]
});
// or if you don't care about MITM (NOT RECOMMENDED):
let client = await connect({
url: `ws://localhost:${port}`,
publicKeys: [{
type: "noverify"
}]
});
// send data
client.send(QoS, data);
// receive data
client.on("data", (QoS, data) => {
// handle data here (data is Uint8Array)
});
FAQs
libp2p-less/hardlinked variant of ProtoV2
The npm package @badaimweeb/js-protov2d receives a total of 0 weekly downloads. As such, @badaimweeb/js-protov2d popularity was classified as not popular.
We found that @badaimweeb/js-protov2d demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.