Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
heapdump-next
Advanced tools
=== add typescript and other
Make a dump of the V8 heap for later inspection.
npm install heapdump-next --save
node-gyp configure build
You need to have g++
ane make
installed to build it.
apt-get install make
apt-get install g++
Load the add-on in your application:
const {Heapdump} = require('heapdump-next');
const heapdump = new Heapdump()
// or
import { Heapdump } from "heapdump-next";
const heapdump = new Heapdump()
The module exports a single writeSnapshot([filename], [callback])
function
that writes out a snapshot. filename
defaults to heapdump-<sec>.<usec>.heapsnapshot
when omitted.
You can specify NODE_HEAPDUMP_FILENAME
env variables, which will be used as template for
filename (include folder) - NODE_HEAPDUMP_FILENAME="/var/heapdumps/heapdump-{sec}.{usec}.snapshot"
,
in case if you want to save snapshots in different folder than application's working directory.
heapdump.writeSnapshot('/var/local/' + Date.now() + '.heapsnapshot');
The function also takes an optional callback function which is called upon completion of the heap dump.
heapdump.writeSnapshot(function(err, filename) {
console.log('dump written to', filename);
});
The snapshot is written synchronously to disk. When the JS heap is large, it may introduce a noticeable "hitch".
Previously, heapdump-next first forked the process before writing the snapshot,
making it effectively asynchronous. However, it broke the comparison view in
Chrome DevTools and is fundamentally incompatible with node.js v0.12. If you
really want the old behavior and know what you are doing, you can enable it
again by setting NODE_HEAPDUMP_OPTIONS=fork
in the environment:
$ env NODE_HEAPDUMP_OPTIONS=fork node script.js
On UNIX platforms, you can force a snapshot by sending the node.js process a SIGUSR2 signal:
$ kill -USR2 <pid>
The SIGUSR2 signal handler is enabled by default but you can disable it
by setting NODE_HEAPDUMP_OPTIONS=nosignal
in the environment:
$ env NODE_HEAPDUMP_OPTIONS=nosignal node script.js
Open Google Chrome and press F12 to open the developer toolbar.
Go to the Profiles
tab, right-click in the tab pane and select
Load profile...
.
Select the dump file and click Open
. You can now inspect the heap snapshot
at your leisure.
Note that Chrome will refuse to load the file unless it has the .heapsnapshot
extension.
On UNIX systems, the rule of thumb for creating a heap snapshot is that it
requires memory twice the size of the heap at the time of the snapshot.
If you end up with empty or truncated snapshot files, check the output of
dmesg
; you may have had a run-in with the system's OOM killer or a resource
limit enforcing policy, like ulimit -u
(max user processes) or ulimit -v
(max virtual memory size).
FAQs
Make a dump of the V8 heap for later inspection.
The npm package heapdump-next receives a total of 1 weekly downloads. As such, heapdump-next popularity was classified as not popular.
We found that heapdump-next demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.