
Research
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.
http-querystring-stringify
Advanced tools
Simple, small and correct querystring serialization-only for the browser or server.
This package is intended for client side code or input data which structure is defined by the application. It has no DoS protection and simplicity and correctness is prioritized over performance.
If you need extreme performance you should consider https://github.com/petkaantonov/querystringparser.
This package was written because serialization seems to happen most often on the client as a single operation and similar performance-focused libraries had trade-offs and bugs while others carried huge dependencies.
const {stringify, appendToUrl} = require('http-querystring-stringify')
stringify({
first: 'John',
last: 'Wayne',
})
// -> first=John&last=Wayne
stringify({
brands: ['KitKat', 'Snickers', 'Bounty'],
})
// -> brands[]=KitKat&brands[]=Snickers&brands[]=Bounty
stringify({
sites: [{name: 'facebook', color: 'blue'}],
})
// -> sites[0][name]=facebook&sites[0][color]=blue
appendToUrl('https://google.com', {
first: 'John',
last: 'Wayne',
})
// -> https://google.com?first=John&last=Wayne
appendToUrl('https://google.com', {
key: undefined,
})
// -> https://google.com
toJSON is respected (like JSON.stringify does)true and false are converted to y or n respectivelynull is represented by an empty stringundefined values will be skipped completely (like JSON.stringify does)Generally there are two types of parsers: those supporting extended nesting and those that just support repeated keys.
const input = {
a: '',
b: 's',
c: ['1', '2', '3'],
d: '&=[]',
e: ['1', '2', ['3', '4']],
f: ['1', {a: '1'}],
}
// deepEqual(parse(stringify(input)), input)
// -> true
parse(
stringify({
a: '',
b: 's',
c: ['1', '2', '3'],
d: '&=[]',
e: ['1', '2', ['3', '4']],
f: ['1', {a: '1'}],
})
)
// -> {
// a: '',
// b: 's',
// d: '&=[]',
// // expect arrays to be collapsed like this
// 'c[]': [ '1', '2', '3' ],
// // expect objects and multi-level arrays to be flattened like this
// 'e[0]': '1',
// 'e[1]': '2',
// 'e[2][]': [ '3', '4' ],
// 'f[0]': '1',
// 'f[1][a]': '1',
// }
FAQs
Create querystrings
The npm package http-querystring-stringify receives a total of 3,915 weekly downloads. As such, http-querystring-stringify popularity was classified as popular.
We found that http-querystring-stringify demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.