
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
coffee-fast-compile
Advanced tools
Module for fast compilation whole directories with very simple API
There are situations when you start thinking for coffee-script support in you lib/module. But interface provided by official cooffee-script module is ugly and don't allow you to watch dir inside your script. This module is built to solve such problems providing simple interface for compiling and watching whole directories built on top nodejs streams.
It just compiles everything from example dir and outputs code to output dir saving all relatives paths.
compile = require('coffee-fast-compile');
var pipe = compile.build('example', 'output', function(files) {
console.log(files, ' was compiled');
});
pipe.on('data', function(file) {
if(file === 'compiled') {
console.log('compiled');
} else {
console.log(file, ' compiled');
}
});
The same as build, but recompiles changed files on the fly. You also can use pipe to monitor results. When initially
called, it invokes build, so first compilation can be long. While watching it only compiles changed files.
compile = require('coffee-fast-compile');
var pipe = compile.watch('example', 'output', function(files) {
console.log(files, ' was compiled');
});
FAQs
Module for fast compilation whole directories with very simple API
We found that coffee-fast-compile demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.