
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
block-stream2
Advanced tools
transform input into equally-sized chunks as output
streams2 version of block-stream
var block = require('block-stream2');
var through = require('through2');
process.stdin
.pipe(block({ size: 16, zeroPadding: true }))
.pipe(through(function (buf, enc, next) {
var str = buf.toString().replace(/[\x00-\x1f]/g, chr);
console.log('buf[' + buf.length + ']=' + str);
next();
}))
;
function chr (s) { return '\\x' + pad(s.charCodeAt(0).toString(16),2) }
function pad (s, n) { return Array(n - s.length + 1).join('0') + s }
$ echo {c,d,f}{a,e,i,o,u}{t,g,r} | node example/stream.js
buf[16]=cat cag car cet
buf[16]=ceg cer cit cig
buf[16]=cir cot cog cor
buf[16]=cut cug cur dat
buf[16]=dag dar det deg
buf[16]=der dit dig dir
buf[16]=dot dog dor dut
buf[16]=dug dur fat fag
buf[16]=far fet feg fer
buf[16]=fit fig fir fot
buf[16]=fog for fut fug
buf[16]=fur\x0a\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
var block = require('block-stream2');
Create a new transform stream b
that outputs chunks of length size
or
opts.size
.
When opts.zeroPadding
is false, do not zero-pad the last chunk.
With npm do:
npm install block-stream2
MIT
FAQs
transform input into equally-sized blocks of output
The npm package block-stream2 receives a total of 224,633 weekly downloads. As such, block-stream2 popularity was classified as popular.
We found that block-stream2 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.