Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Node.js implementation of FarmHash, Google's family of very fast hash functions
The farmhash npm package provides fast, non-cryptographic hash functions for strings and binary data. It is based on Google's FarmHash family of hash functions, which are designed for high performance and reliability.
Hashing a string
This feature allows you to generate a 32-bit hash from a given string. The hash function is optimized for speed and can be used for tasks like data partitioning or quick lookups.
const farmhash = require('farmhash');
const hash = farmhash.hash32('Hello, world!');
console.log(hash);
Hashing a buffer
This feature allows you to generate a 32-bit hash from a buffer. This is useful for hashing binary data or files.
const farmhash = require('farmhash');
const buffer = Buffer.from('Hello, world!');
const hash = farmhash.hash32(buffer);
console.log(hash);
Hashing a string to 64-bit
This feature allows you to generate a 64-bit hash from a given string. The 64-bit hash provides a larger hash space, reducing the likelihood of collisions.
const farmhash = require('farmhash');
const hash = farmhash.hash64('Hello, world!');
console.log(hash);
Hashing a buffer to 64-bit
This feature allows you to generate a 64-bit hash from a buffer. This is useful for applications requiring a larger hash space for binary data.
const farmhash = require('farmhash');
const buffer = Buffer.from('Hello, world!');
const hash = farmhash.hash64(buffer);
console.log(hash);
MurmurHash is a non-cryptographic hash function suitable for general hash-based lookup. It is known for its good distribution and performance. Compared to farmhash, MurmurHash is also very fast but may not be as optimized for certain hardware architectures.
xxHash is an extremely fast non-cryptographic hash algorithm, working at speeds close to RAM limits. It is designed for speed and is often faster than farmhash, but farmhash may offer better distribution properties in some cases.
CityHash, like FarmHash, is developed by Google and provides fast hashing for strings. It is similar to FarmHash but is an older version. FarmHash is designed to be more portable and faster on newer hardware.
Node.js implementation of Google's FarmHash family of very fast hash functions.
FarmHash is the successor to CityHash. Functions in the FarmHash family are not suitable for cryptography. A fast, cryptographically-secure alternative is HighwayHash.
The 32-bit methods return a Number
,
the 64-bit methods return a BigInt
and the 128-bit methods are not implemented.
This module uses FarmHash v1.1.0 (2015-03-01). It has been tested with Node.js 16, 18, 20 and 22 on Linux (glibc, musl), macOS (x64, arm64) and Windows (x86, x64).
Pre-compiled binaries are provided for
Intel CPUs with SSE4.2 intrinsics
and Apple ARM64 CPUs.
Use the npm install --build-from-source
flag to gain performance benefits
on more modern CPUs such as those with AVX intrinsics.
npm install farmhash
yarn add farmhash
pnpm add farmhash
const farmhash = require('farmhash');
const hash = farmhash.hash32('test');
console.log(typeof hash); // 'number'
const hash = farmhash.hash64(new Buffer('test'));
console.log(typeof hash); // 'bigint'
const hash = farmhash.hash64WithSeed('test', 123);
console.log(typeof hash); // 'bigint'
const hash = farmhash.fingerprint32(new Buffer('test'));
console.log(typeof hash); // 'number'
const hash = farmhash.fingerprint64('test');
console.log(typeof hash); // 'bigint'
const hash = farmhash.fingerprint64signed('test');
console.log(typeof hash); // 'bigint'
The hash methods are platform dependent. Different CPU architectures, for example 32-bit vs 64-bit, Intel vs ARM, SSE4.2 vs AVX might produce different results for a given input.
input
is the Buffer
or String
to hash.Returns a Number
containing the 32-bit unsigned integer hash value of input
.
input
is the Buffer
or String
to hash.seed
is an integer Number to use as a seed.Returns a Number
containing the 32-bit unsigned integer hash value of input
.
input
is the Buffer
or String
to hash.Returns a BigInt
containing the 64-bit unsigned integer hash value of input
.
input
is the Buffer
or String
to hash.seed
is an integer Number
to use as a seed.Returns a BigInt
containing the 64-bit unsigned integer hash value of input
.
input
is the Buffer
or String
to hash.seed1
and seed2
are both an integer Number
to use as seeds.Returns a BigInt
containing the 64-bit unsigned integer hash value of input
.
The fingerprint methods are platform independent, producing the same results for a given input on any machine.
input
is the Buffer
or String
to fingerprint.Returns a Number
containing the 32-bit unsigned integer fingerprint value of input
.
input
is the Buffer
or String
to fingerprint.Returns a BigInt
containing the 64-bit unsigned integer fingerprint value of input
.
input
is the Buffer
or String
to fingerprint.Returns a BigInt
containing the 64-bit signed integer fingerprint value of input
.
This matches the signed behaviour of Google BigQuery's FARM_FINGERPRINT function.
npm test
Copyright 2014 Lovell Fuller and contributors.
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
Copyright 2014, 2015, 2016, 2017 Google, Inc.
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
FAQs
Node.js implementation of FarmHash, Google's family of very fast hash functions
We found that farmhash demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.