
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
ip2location-native
Advanced tools
This library is a complete re-write of IP2LOCATION database client. Built for speed.
Data structures learnt from the IP2Location C library:
http://www.ip2location.com/developers/c-7
Sample binary databases are available here.
npm install ip2location-native
Location = require('ip2location-native')
location = new Location('path/to/ip2location_database.bin', 'mmap')
location.query('8.8.8.8')
{ country_short: ....,
country_long: ....,
region: ....,
city: ....,
latitude: ....,
longitude: ....,
elevation: .... }
# retrieve only country short, latitude and longitude
location.query('8.8.8.8', Location.COUNTRY_SHORT | Location.LATITUDE | Location.LONGITUDE)
{ country_short: ....,
latitude: ....,
longitude: .... }
# query binary ip
location.query( new Buffer([8,8,4,4]) )
# free resources
location.close()
The second, optional constructor argument configures database access mode. The default mode is "file" - without caching. It conserves memory but reading is done with blocking IO.
location = new Location('path/to/ip2location_database.bin', 'cache')
location.mode == "cache"
location = new Location('path/to/ip2location_database.bin', 'mmap')
location.mode == "mmap"
location = new Location('path/to/ip2location_database.bin', 'shared')
location.mode == "shared"
Every other process calling new Location(dbname, "shared") will try to re-open
existing shared memory.
The default name used for the shared memory is "/IP2location_Shm". However you are free to pick another (the name must begin with a slash - "/")
location = new Location('path/to/ip2location_database.bin', '/MyDatabase1')
location.mode == "shared"
location.info().sharedname == "/MyDatabase1"
A call to location.close() will not delete the shared memory, it will only
detach process from it. To delete the shared memory call:
location.deleteShared()
Before close().
When deleteShared is called, and if any other process is attached to the
shared memory, the function will only delete the inode of the shared memory.
The other processes will continue to use the shared memory and it will be freed
only after the last process is detached from it (closes database).
Please refer to shm_open and shm_unlink man pages for more info.
Last process calling location.close() will delete the shared memory.
On tested system the library in default IO mode with IP2LOCATION-LITE-5 database spends on average 25µs per ip lookup returning all available record entities. With caching enabled it speeds up to 5µs / lookup (~200 000 / s).
This is about at least 200 times faster then the pure js IP2Location module.
Further speed up is available by limiting the set of fields retrieved from
the database with the second argument to query().
node test/bench IP2LOCATION-DATABASE.BIN access_mode iterations mask
The library takes additional precaution when dealing with database files. The format verification routine prevents accessing wrong format or corrupted files.
The drop-in module allows you to replace the official IP2Location library without touching your code, except for:
var ip2location = require('ip2location-native/dropin')
ip2location.IP2Location_init('path/to/ip2location_database.bin')
ip2location.IP2Location_get_all('8.8.8.8')
Do you want to know all available unique location property values?
Sorted, grouped by property type and structured? No problem.
With this module it's possible to dump database dictionaries using
createDictionary([FIELD_MASK]) method.
var dict = location.createDictionary(Location.COUNTRY_LONG|Location.REGION|Location.CITY)
dict._index.indexOf('PL') == 174
dict.PL.country_long == 'Poland'
dict.PL.region._index.indexOf('Mazowieckie') == 6
dict.PL.region.Mazowieckie.indexOf('Warsaw') == 251
This module was tested on Linux (x64), OS X and MS Windows (x64 and x86) with node v6, v7, v8, v9, v10, v11 and v12.
LGPL-3.0
FAQs
native IP2Location library for node.js
The npm package ip2location-native receives a total of 21 weekly downloads. As such, ip2location-native popularity was classified as not popular.
We found that ip2location-native demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.