
Research
Node.js Fixes AsyncLocalStorage Crash Bug That Could Take Down Production Servers
Node.js patched a crash bug where AsyncLocalStorage could cause stack overflows to bypass error handlers and terminate production servers.
esm-http-server
Advanced tools
A server that can intelligently handle ESM specifiers.
# serve from fs
PORT=8080 esm-http-server
# serve as proxy
PORT=8081 HTTP_PROXY=http://localhost:8080/serve/ esm-http-server
All files will be served under the /serve/ prefix, so a index.html file at the root of the location providing content would be available at /serve/index.html.
By default specifiers follow the WHATWG module resolution algorithm.
PORT=8080 esm-http-server --loader loader.js
You can inspect the shape of the default loader to see what a custom one needs to provide. These loaders are designed to be composable and multiple --loader flags are allowed and are constructed from left to right with the left as the final loader and the right as the first loader that intercepts requests.
Since the server only intercepts JS MIME types, if you serve non-module JS under a different MIME it will not be intercepted.
FAQs
http server with esm loader hooks
The npm package esm-http-server receives a total of 0 weekly downloads. As such, esm-http-server popularity was classified as not popular.
We found that esm-http-server demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Node.js patched a crash bug where AsyncLocalStorage could cause stack overflows to bypass error handlers and terminate production servers.

Research
/Security News
A malicious Chrome extension steals newly created MEXC API keys, exfiltrates them to Telegram, and enables full account takeover with trading and withdrawal rights.

Security News
CVE disclosures hit a record 48,185 in 2025, driven largely by vulnerabilities in third-party WordPress plugins.