
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
@office-open/pptx
Advanced tools
Generate, parse, and patch .pptx presentations with a declarative TypeScript API
Generate and parse .pptx presentations with a declarative TypeScript API. Works in Node.js and browsers.
parsePresentation for round-trip workflows# pnpm
pnpm add @office-open/pptx
# npm
npm install @office-open/pptx
# yarn
yarn add @office-open/pptx
# bun
bun add @office-open/pptx
import { generatePresentation } from "@office-open/pptx";
import { writeFileSync } from "node:fs";
const buffer = await generatePresentation({
slides: [
{
children: [
{
shape: {
textBody: {
children: [{ paragraph: { children: ["Hello World"] } }],
},
fill: "4472C4",
x: 100,
y: 100,
width: 600,
height: 400,
},
},
],
},
],
});
writeFileSync("presentation.pptx", buffer);
Read existing .pptx files and re-create them as PresentationOptions:
import { parsePresentation, generatePresentation } from "@office-open/pptx";
import { readFileSync, writeFileSync } from "node:fs";
const opts = parsePresentation(new Uint8Array(readFileSync("input.pptx")));
// Modify parsed data, then re-generate
const buffer = await generatePresentation(opts);
writeFileSync("output.pptx", buffer);
Performance vs PptxGenJS (higher ops/s is better, Windows 11 / Node 24).
Default = XML DEFLATE level 1 (SuperFast); media is split by type, matching MS Office PowerPoint — already-compressed formats (PNG/JPEG/GIF) are STOREd, the rest (EMF/WMF/BMP/TIFF/…) use DEFLATE level 6 / Normal (verified on a real MS Office file). All STORE = no compression ({ compression: { xml: 0, media: 0 } }). PptxGenJS (async only) defaults to STORE (via JSZip), supports DEFLATE via compression: true (applies to ALL entries including images).
// Default (matches MS Office)
await generatePresentation(options);
// All STORE (no compression)
await generatePresentation(options, { compression: { xml: 0, media: 0 } });
Create + toBuffer (end-to-end)
| Scenario | Default sync | Default async | All STORE sync | All STORE async | PptxGenJS DEFLATE | PptxGenJS STORE |
|---|---|---|---|---|---|---|
| Simple (2 shapes) | 1,176 ops/s | 646 ops/s | 4,345 ops/s | 3,969 ops/s | 185 ops/s | 199 ops/s |
| Styled shapes (20) | 1,182 ops/s | 660 ops/s | 4,197 ops/s | 4,224 ops/s | 196 ops/s | 194 ops/s |
| Table (10x5) | 1,471 ops/s | 716 ops/s | 8,044 ops/s | 7,416 ops/s | 928 ops/s | 1,020 ops/s |
| Full featured | 1,033 ops/s | 639 ops/s | 2,924 ops/s | 2,598 ops/s | 107 ops/s | 102 ops/s |
Large Files — Create + toBuffer
| Scenario | Default sync | Default async | All STORE sync | All STORE async | PptxGenJS DEFLATE | PptxGenJS STORE |
|---|---|---|---|---|---|---|
| 30 slides x 20 shapes | 255 ops/s | 143 ops/s | 567 ops/s | 547 ops/s | 127 ops/s | 135 ops/s |
| 30 slides x 10 images | 120 ops/s | 84.4 ops/s | 169 ops/s | 163 ops/s | 0.34 ops/s | 0.34 ops/s |
| 100x10 table | 603 ops/s | 446 ops/s | 1,053 ops/s | 1,052 ops/s | 135 ops/s | 121 ops/s |
| 50 slides full | 86.7 ops/s | 54.4 ops/s | 126 ops/s | 128 ops/s | 1.01 ops/s | 1.02 ops/s |
Large File (~100MB) — Mixed Content
40 slides x (2 shapes + 2 mixed-size images + 3x3 table).
| Scenario | Default sync | Default async | All STORE sync | All STORE async | PptxGenJS DEFLATE | PptxGenJS STORE |
|---|---|---|---|---|---|---|
| 40 slides mixed | 24.5 ops/s | 22.4 ops/s | 25.3 ops/s | 25.0 ops/s | 0.24 ops/s | 0.24 ops/s |
Check the demo folder for working examples covering every feature.
FAQs
Generate, parse, and patch .pptx presentations with a declarative TypeScript API
The npm package @office-open/pptx receives a total of 84 weekly downloads. As such, @office-open/pptx popularity was classified as not popular.
We found that @office-open/pptx demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.