
Security News
Critical Security Vulnerability in React Server Components
React disclosed a CVSS 10.0 RCE in React Server Components and is advising users to upgrade affected packages and frameworks to patched versions now.
@thumbmarkjs/thumbmarkjs
Advanced tools
  .
🙏 Please don't do evil. ThumbmarkJS is meant to be used for good. Use this to prevent scammers and spammers for example. If you see this library being used for evil, contact me.
🕺 Join the Thumbmark Discord channel
You can help this project by visiting the demo page that logs your fingerprint for analysis. The logged fingerprint data is only used to improve this library. Visit the page from the link: Show and log my fingerprint
The library works very well to distinguish common browsers.
Data collected through this demo page show an accuracy of 90.5%-95.5% (95% confidence interval) in identifying a unique visitor correctly.
Mileage may vary though. Mac/Safari users tend to clash more than Windows users, and it does depend on your audience.
Transpiled bundles are available now on JSDelivr.
Supported module formats:
<script src="https://cdn.jsdelivr.net/npm/@thumbmarkjs/thumbmarkjs/dist/thumbmark.umd.js"></script>
<script>
ThumbmarkJS.getFingerprint().then(
function(fp) {
console.log(fp);
}
);
</script>
<!-- or -->
<script>
import('https://cdn.jsdelivr.net/npm/@thumbmarkjs/thumbmarkjs/dist/thumbmark.umd.js')
.then(() => {
ThumbmarkJS.getFingerprint().then((fp) => { console.log(fp)})
})
</script>
You can also call ThumbmarkJS.getFingerprintData() to get a full JSON object with all its components.
You can use the setOption method to change the behavior of the library. Currently it takes only one option.
| option | type | example | what it does |
|---|---|---|---|
| exclude | string[] | ['webgl', 'system.browser.version'] | Removes components from the fingerprint hash. An excluded top-level component improves performance. |
| include | string[] | ['webgl', 'system.browser.version'] | Only includes the listed components. exclude still excludes included components. |
| timeout | integer | 1000 | Default is 1000. Component timeout in milliseconds. |
| logging | boolean | true | Default is true. Setting to false disables the anonymous 0.01% log sampling that is used to improve the library. |
example usage:
ThumbmarkJS.setOption('exclude', ['webgl', 'system.browser.version'])
You can add custom components to the hash with includeComponent, which takes two parameters, the key being the key of the component in the JSON and the function that returns the value (a string, a number or a JSON object). So for example, if you wanted to include an IP address in the components, you could do it like so:
function fetchIpAddress() {
return new Promise((resolve, reject) => {
fetch('http://checkip.amazonaws.com')
.then(response => {
if (!response.ok) {
throw new Error('Network response was not ok');
}
return response.text();
})
.then(ip => resolve({'ip_address': ip.trim()}))
.catch(error => {
console.error('There was a problem with the fetch operation:', error);
reject(error);
});
});
}
ThumbmarkJS.includeComponent('tcp', fetchIpAddress);
The function is expected to return a Promise, but it seems it works without, too.
NOTE I don't recommend making calls to external websites like this, since it adds a huge lag to running the fingerprint. You can see for yourself by running ThumbmarkJS.getFingerprintPerformance(). But it's possible.
Installing from NPM:
npm install @thumbmarkjs/thumbmarkjs
and in your code
import { getFingerprint } from '@thumbmarkjs/thumbmarkjs'
To implement ThumbmarkJS in a Next.js app, you can use a component like this.
:warning: note, thumbmarkjs was published up to version 0.12.1 to NPM package thumbmarkjs and from v0.12.1 onwards will be published under @thumbmarkjs/thumbmarkjs. I'll occasionally update the old location, but please update your imports.
But bear in mind that the library is meant to be running in the browser. Let me know if the library fails on a server side import. However, getFingerprint() is not meant to be called server side.
Clone this repo and then run
npm run install
npm run build
Simply going to the Show and log my fingerprint-page helps a lot. The logging is all anonymous and only used to develop this library. Let me know if you run into any errors by opening an issue. The discussion section is also open.
Test cases you can try:
if you see a fingerprint change when it shouldn't, you can use this JSON Diff Finder tool to check what causes the diff.
I wanted to create something that's easy to build, extend and use. If you're interested in how the library works, the structure is very simple.
Have a look at the technical_details
FAQs
  
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
React disclosed a CVSS 10.0 RCE in React Server Components and is advising users to upgrade affected packages and frameworks to patched versions now.

Research
/Security News
We spotted a wave of auto-generated “elf-*” npm packages published every two minutes from new accounts, with simple malware variants and early takedowns underway.

Security News
TypeScript 6.0 will be the last JavaScript-based major release, as the project shifts to the TypeScript 7 native toolchain with major build speedups.