
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
@musicglue/async-hook
Advanced tools
#async-hook
Inspect the life of handle objects in node
This is high level abstraction of the currently undocumented node API called AsyncWrap. It patches some issues, makes the API more uniform and allows multiply hooks to be created.
I personally hope that most of this will make it into nodecore, but for now it exists as an userland module.
For the details of how AsyncWrap works and by extension how this module works, please see the semi-official AsyncWrap documentation: https://github.com/nodejs/tracing-wg/blob/master/docs/AsyncWrap/README.md
const asyncHook = require('async-hook');
The function arguments are:
function init(uid, handle, provider, parentUid, parentHandle) { /* your code */ }
function pre(uid, handle) { /* your code */ }
function post(uid, handle) { /* your code */ }
function destroy(uid) { /* your code */ }
To add hooks:
asyncHook.addHooks({ init, pre, post, destroy });
To remove hooks:
asyncHooks.removeHooks({ init, pre, post, destroy });
All properties in the hooks object that addHooks and removeHooks takes are
optional.
The providers map is exposed as:
asyncHook.providers[provider];
You can enable and disable all hooks by using asyncHook.enable() and
asyncHook.disable(). By default it is disabled.
Be careful about disabling the hooks, this will most likely conflict with other
modules that uses async-hook.
FAQs
Inspect the life of handle objects in node
We found that @musicglue/async-hook demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.