
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
JavaScript / TypeScript tools to fetch Google search results without an API key.
Modern JavaScript / TypeScript tools for fetching and parsing Google search results
Usage • Documentation • Disclaimer • Mirror
Not supported in browser environments.
npm install google-sr
# Or with pnpm/yarn or https://bun.sh
pnpm add google-sr
yarn add google-sr
bun add google-sr
# we also provide builds on https://jsr.io/@typical/google-sr/
npx jsr add @typical/google-sr
Currently this package provides both CommonJS (CJS) and ES Modules (ESM) builds.
Starting in version 7.x (subject to change), we plan to publish ESM-only releases and remove the CJS build.
As a result, you will no longer be able to use require() to import this package; you must use import instead.
(If you’re on Node.js v20 or later, you can still use require() with ESM modules natively. See release note)
Note: This only affects Node.js users. Runtimes like Bun and Deno already support ESM natively.
See this gist and our GitHub discussion for migration help.
google-sr is modular, use only the parsers relevant to your search. Here’s a simple example:
import { search, OrganicResult, TranslateResult, ResultTypes } from "google-sr";
const results = await search({
query: "translate hello to japanese",
parsers: [TranslateResult, OrganicResult],
});
console.log(results[0].type === ResultTypes.TranslateResult); // true
console.log(results);
[
{
type: 'TRANSLATE',
sourceLanguage: 'English (detected)',
translationLanguage: 'Japanese',
sourceText: 'hello',
translatedText: 'こんにちは'
},
{
type: 'ORGANIC',
link: '...',
description: "Konnichiwa – ...",
title: '18 ...'
}
]
More examples available at: apps/examples
Tests use vitest. Run:
pnpm run test
This project is not sponsored, endorsed, or affiliated with Google in any way.
This repository is provided "as is" without warranty of any kind and is intended solely for educational and research purposes. The authors and contributors assume no responsibility for any issues, damages, or losses that may arise from its use.
By using this project, you acknowledge that you are solely responsible for complying with applicable laws and platform Terms of Service. Use at your own discretion and risk.
This repository and the code inside it is licensed under the Apache-2.0 License. Read LICENSE for more information.
FAQs
JavaScript / TypeScript tools to fetch Google search results without an API key.
The npm package google-sr receives a total of 966 weekly downloads. As such, google-sr popularity was classified as not popular.
We found that google-sr demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.