Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
async-hook-jl
Advanced tools
#async-hook-jl
Inspect the life of handle objects in node
This is high level abstraction of the currently undocumented node API called AsyncWrap. It patches some issues, makes the API more uniform and allows multiply hooks to be created.
I personally hope that most of this will make it into nodecore, but for now it exists as an userland module.
For the details of how AsyncWrap works and by extension how this module works, please see the semi-official AsyncWrap documentation: https://github.com/nodejs/diagnostics/blob/master/tracing/AsyncWrap/README.md
const asyncHook = require('async-hook-jl');
The function arguments are:
function init(uid, handle, provider, parentUid, parentHandle) { /* your code */ }
function pre(uid, handle) { /* your code */ }
function post(uid, handle, didThrow) { /* your code */ }
function destroy(uid) { /* your code */ }
To add hooks:
asyncHook.addHooks({ init, pre, post, destroy });
To remove hooks:
asyncHooks.removeHooks({ init, pre, post, destroy });
All properties in the hooks object that addHooks
and removeHooks
takes are
optional.
The providers map is exposed as:
asyncHook.providers[provider];
You can enable and disable all hooks by using asyncHook.enable()
and
asyncHook.disable()
. By default it is disabled.
Be careful about disabling the hooks, this will most likely conflict with other
modules that uses async-hook-jl
.
FAQs
Inspect the life of handle objects in node
We found that async-hook-jl demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.