
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
@huggingface/xetchunk-wasm
Advanced tools
Content-defined chunking and hashing for Hugging Face Xet storage
Content-defined chunking and hashing for Hugging Face Xet storage, matching the Rust reference implementation.
Uses gearhash-jit for fast GEAR rolling hash boundary detection and @huggingface/blake3-jit for BLAKE3 chunk hashing.
import { createChunker, nextBlock, finalize, getChunks, hashToHex, xorbHash, fileHash } from '@huggingface/xetchunk-wasm';
// One-shot: chunk all data at once
const data = new Uint8Array(1_000_000);
const chunks = getChunks(data);
console.log(`${chunks.length} chunks`);
console.log('xorb hash:', hashToHex(xorbHash(chunks)));
console.log('file hash:', hashToHex(fileHash(chunks)));
// Streaming: process data incrementally
const chunker = createChunker();
for await (const buf of source) {
const chunks = nextBlock(chunker, buf);
for (const chunk of chunks) {
console.log(hashToHex(chunk.hash), chunk.length);
}
}
const lastChunk = finalize(chunker);
createChunker(targetChunkSize?: number) — Create a chunker (default 64KB target).nextBlock(chunker, data: Uint8Array): Chunk[] — Feed data, get complete chunks.finalize(chunker): Chunk | null — Flush remaining data as a final chunk.getChunks(data: Uint8Array, targetChunkSize?: number): Chunk[] — One-shot convenience.All hash functions return Uint8Array (32 bytes). Use hashToHex() to convert to hex strings.
xorbHash(chunks: Chunk[]): Uint8Array — Merkle tree hash over chunks (matches Rust xorb_hash).fileHash(chunks: Chunk[]): Uint8Array — File-level hash (matches Rust file_hash).hmac(hash: Uint8Array, key: Uint8Array): Uint8Array — BLAKE3 keyed hash (matches Rust DataHash::hmac).verificationHash(chunkHashes: Uint8Array[]): Uint8Array — Range verification hash (matches Rust range_hash_from_chunks).hashToHex(hash: Uint8Array): string — Convert 32-byte hash to hex string.hexToBytes(hex: string): Uint8Array — Convert 64-char hex string to 32 bytes.pnpm --filter @huggingface/xetchunk-wasm bench
# or with a specific file:
pnpm --filter @huggingface/xetchunk-wasm bench path/to/large-file
FAQs
Content-defined chunking and hashing for Hugging Face Xet storage
We found that @huggingface/xetchunk-wasm demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.