
Research
TeamPCP Compromises Telnyx Python SDK to Deliver Credential-Stealing Malware
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.
exponential-backoff
Advanced tools
A utility that allows retrying a function with an exponential delay between attempts.
A utility that allows retrying a function with an exponential delay between attempts.
npm i exponential-backoff
The backOff<T> function takes a promise-returning function to retry, and an optional BackOffOptions object. It returns a Promise<T>.
function backOff<T>(
request: () => Promise<T>,
options?: BackOffOptions
): Promise<T>;
Here is an example retrying a function that calls a hypothetical weather endpoint:
import { backOff } from "exponential-backoff";
function getWeather() {
return fetch("weather-endpoint");
}
async function main() {
try {
const response = await backOff(() => getWeather());
// process response
} catch (e) {
// handle error
}
}
main();
Migrating across major versions? Here are our breaking changes.
BackOffOptionsdelayFirstAttempt?: boolean
Decides whether the startingDelay should be applied before the first call. If false, the first call will occur without a delay.
Default value is false.
jitter?: JitterType | string
Decides whether a jitter should be applied to the delay. Possible values are full and none.
Default value is none.
maxDelay?: number
The maximum delay, in milliseconds, between two consecutive attempts.
Default value is Infinity.
numOfAttempts?: number
The maximum number of times to attempt the function.
Default value is 10.
Minimum value is 1.
retry?: (e: any, attemptNumber: number) => boolean | Promise<boolean>
The retry function can be used to run logic after every failed attempt (e.g. logging a message, assessing the last error, etc.). It is called with the last error and the upcoming attempt number. Returning true will retry the function as long as the numOfAttempts has not been exceeded. Returning false will end the execution.
Default value is a function that always returns true.
startingDelay?: number
The delay, in milliseconds, before executing the function for the first time.
Default value is 100 ms.
timeMultiple?: number
The startingDelay is multiplied by the timeMultiple to increase the delay between reattempts.
Default value is 2.
The 'retry' package provides similar functionality for implementing retry strategies. It supports both time-based and event-based retries. It is more low-level compared to 'exponential-backoff' and requires more setup but offers more flexibility.
The 'async-retry' package is another alternative that offers a simple API for retrying asynchronous functions, with support for custom retries and exponential backoff. It is similar to 'exponential-backoff' but has a slightly different API design.
The 'promise-retry' package allows you to retry a promise-returning or async function, with an API that is very similar to 'async-retry'. It provides a flexible approach to handling retries with promises.
FAQs
A utility that allows retrying a function with an exponential delay between attempts.
The npm package exponential-backoff receives a total of 24,494,659 weekly downloads. As such, exponential-backoff popularity was classified as popular.
We found that exponential-backoff demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 15 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.

Security News
/Research
Widespread GitHub phishing campaign uses fake Visual Studio Code security alerts in Discussions to trick developers into visiting malicious website.