
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
itchio-downloader
Advanced tools
GitHub Repository: itchio-downloader on GitHub
npm Package: itchio-downloader on npm
Itchio-Downloader provides a small CLI and library for downloading free games from itch.io. Games can be fetched by URL or by name and author—no API key or GUI is required. See the API Reference for all functions and types. More guides are available in docs/README.md.
I built this tool to create a launcher for free games and released it so others can do the same. It's the only known way to download itch.io games programmatically without an API key or developer access.
Only download free games and follow the itch.io Terms of Service. Don't bypass payment restrictions. This project isn't affiliated with or endorsed by itch.io.
Requires Node.js 18+. For a full setup guide see docs/Installation.md.
Install the package:
pnpm add itchio-downloader
# or install globally for the CLI
pnpm add -g itchio-downloader
# or
yarn add itchio-downloader
If installed globally you can run the command directly:
itchio-downloader --help
See docs/CLI.md for CLI options and docs/Debugging.md for verbose logging.
const { downloadGame } = require('itchio-downloader');
Download a game by URL or by name and author:
// Using a direct URL:
await downloadGame({ itchGameUrl: 'https://baraklava.itch.io/manic-miners' });
// Using name and author and optional params:
await downloadGame({
name: 'manic-miners',
author: 'baraklava',
downloadDirectory: 'full file path', // Optional
});
Provide an array to download multiple games. Mix URLs or name/author combinations. Use concurrency
to limit downloads or set parallel: true
to run them all concurrently:
async function downloadMultipleGames() {
const gameParams = [
{ name: 'manic-miners', author: 'baraklava' },
{ itchGameUrl: 'https://anotherdev.itch.io/another-game' },
{ itchGameUrl: 'https://moregames.itch.io/better-game', parallel: true },
];
await downloadGame(gameParams, 2); // up to 2 downloads or set parallel to run all at once
}
downloadMultipleGames();
See docs/Advanced-Usage.md for more concurrency and custom path examples.
Provide an onProgress
callback to monitor download progress:
await downloadGame({
itchGameUrl: 'https://baraklava.itch.io/manic-miners',
onProgress: ({ bytesReceived, totalBytes }) => {
if (totalBytes) {
const pct = ((bytesReceived / totalBytes) * 100).toFixed(1);
console.log(`Progress: ${pct}%`);
}
},
});
The CLI displays similar progress automatically when run directly.
Build the CLI with pnpm run build-cli
, then run itchio-downloader
with your options. The --concurrency
flag limits how many downloads run at once when supplying a list of games. Full details are in docs/CLI.md.
# Example limiting concurrency
itchio-downloader --url "https://baraklava.itch.io/manic-miners" --concurrency 2
The downloadGame
function accepts the following parameters within DownloadGameParams
:
name
: Game name (use with author
).author
: Author's username.itchGameUrl
: Direct URL to the game.desiredFileName
: Custom file name.downloadDirectory
: Where to save files.writeMetaData
: Save metadata JSON (default true
).concurrency
: Number of downloads at once when using an array.parallel
: If true, run all downloads concurrently with Promise.all
.onProgress
: Callback invoked with download progress information.export type DownloadGameParams = {
name?: string,
author?: string,
desiredFileName?: string,
downloadDirectory?: string,
itchGameUrl?: string,
writeMetaData?: boolean,
parallel?: boolean
onProgress?: (info: DownloadProgress) => void
};
export type DownloadGameResponse = {
status: boolean,
message: string,
metaData?: IItchRecord,
metadataPath?: string,
filePath?: string
};
Example response:
const response = {
status: true,
message: 'Download and file operations successful.',
metadataPath: 'C:\\Users\\Aquataze\\Desktop\\itchDownloader\\testOutput\\manic-miners\\manic-miners-metadata.json',
filePath: 'C:\\Users\\Aquataze\\Desktop\\itchDownloader\\testOutput\\manic-miners\\ManicMinersV1.0.zip',
metaData: {
title: 'Manic Miners: A LEGO Rock Raiders remake',
coverImage: 'https://img.itch.zone/aW1nLzEzMTQ1NzA1LnBuZw==/315x250%23c/i%2BJ4qs.png',
authors: [[Object]],
tags: [],
id: 598634,
commentsLink: 'https://baraklava.itch.io/manic-miners/comments',
selfLink: 'https://baraklava.itch.io/manic-miners',
author: 'baraklava',
name: 'manic-miners',
domain: '.itch.io',
itchGameUrl: 'https://baraklava.itch.io/manic-miners',
itchMetaDataUrl: 'https://baraklava.itch.io/manic-miners/data.json'
}
};
More documentation:
Contributions are welcome! Fork the repo and submit a pull request. For major changes, open an issue first. See CONTRIBUTING.md for details.
Update tests as needed.
Run pnpm test
and build the CLI with pnpm run build-cli
.
Publishing runs the prepublishOnly
script to build the CLI.
Clone the repository and install dependencies:
git clone https://github.com/Wal33D/itchio-downloader.git
cd itchio-downloader
pnpm install
pnpm install
installs ts-jest
and other dev dependencies required for the test suite. Running tests without installing these packages will result in a "Preset ts-jest not found" error.
Run the tests with:
pnpm test
package.json
.CHANGELOG.md
.pnpm publish
(the prepublishOnly
script builds the CLI).Dependabot monitors dependencies and opens PRs.
ISC License.
FAQs
Programatically download games from itch.io using Node
The npm package itchio-downloader receives a total of 12 weekly downloads. As such, itchio-downloader popularity was classified as not popular.
We found that itchio-downloader demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.