Security News
Supply Chain Attack Detected in Solana's web3.js Library
A supply chain attack has been detected in versions 1.95.6 and 1.95.7 of the popular @solana/web3.js library.
isobmff-inspector
Advanced tools
The ISOBMFF-inspector is a simple module compatible with Node.js and JavaScript to facilitate ISOBMFF file parsing.
This is most of all useful for debugging purposes.
You can see it working online through the demo page of the AISOBMFFWVDFBUTFAII , available here . AISOBMFFWVDFBUTFAII is an online ISOBMFF visualizer based on this parser.
You can install it through npm:
npm install isobmff-inspector
Then you can then directly use the inspector in your JavaScript or Node file:
import inspectISOBMFF from "isobmff-inspector";
// The given file can be of either of those types:
// - ArrayBuffer
// - Any TypedArray (Uint8Array, Uint16Array, etc.)
const parsed = inspectISOBMFF(MY_ISOBMFF_FILE);
console.log(parsed);
In the previous example, parsed
will have something like the following
structure:
[ // boxes, in the order they are encountered
{
alias: "styp", // "short" name of the box
name: "Segment Type Box", // more human-readable name for the box
size: 24, // size, in bytes
values: [ // values in the box, in the order they are encountered
{
name: "major-brand", // name of the value
value: "iso6" // ...value. Displayable one are JS strings
},
{
name: "minor_version",
value: 0 // Number values are usually JS Numbers
},
{
name: "compatible_brands",
value: "iso6, msdh", // here brands are separated by a comma
}
]
},
{
alias: "moof",
name: "Movie Fragment Box",
size: 788,
children: [ // children boxes, in the order they are encountered
{
alias: "mfhd",
name: "Movie Fragment Header Box",
values: [
{
name: "version",
value: 0
}
{
name: "flags",
value: 0
},
{
name: "sequence_number",
value: 2
}
]
}
]
}
// ...
]
Note: You can also add to your page or your console the script defined in
dist/bundle.js
.
You will then have an inspectISOBMFF
function defined which has the same API
as above.
The inspector only parses the following ISOBMFF boxes for now:
I plan to support each one of them but UUIDs (I may add support for some of them in the future, for example for Smooth Streaming ones).
You can help me to add parsing logic for other boxes by updating the
src/boxes
directory.
You can base yourself on already-defined boxes. Each of the parser
functions
there receive a bufferReader
object.
This object is obtained by giving the box's content as an Uint8Array
to the
createBufferReader
function defined and documented in
src/utils/buffer_reader.js
.
FAQs
Simple ISOBMFF parser, compatible with JavaScript and Node.JS
The npm package isobmff-inspector receives a total of 4 weekly downloads. As such, isobmff-inspector popularity was classified as not popular.
We found that isobmff-inspector demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
A supply chain attack has been detected in versions 1.95.6 and 1.95.7 of the popular @solana/web3.js library.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.