Research
Security News
Threat Actor Exposes Playbook for Exploiting npm to Build Blockchain-Powered Botnets
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
The klaw-sync npm package is a Node.js module that allows users to recursively walk ('klaw') through the file system synchronously. It is useful for tasks such as reading all files in a directory and its subdirectories, filtering files by certain criteria, and obtaining file stats in a synchronous manner.
Recursive file listing
This feature allows you to list all files and directories within a given directory recursively. The example code lists all paths within '/some/directory'.
const klawSync = require('klaw-sync');
const paths = klawSync('/some/directory');
console.log(paths);
Filtering files
This feature allows you to filter the files and directories based on a custom function. In the example, only '.txt' files are listed.
const klawSync = require('klaw-sync');
const path = require('path');
const filterFn = item => path.extname(item.path) === '.txt';
const txtFiles = klawSync('/some/directory', { filter: filterFn });
console.log(txtFiles);
Including file stats
This feature allows you to include file stats in the output. The example code lists directories (excluding files) within '/some/directory' and includes their stats.
const klawSync = require('klaw-sync');
const pathsWithStats = klawSync('/some/directory', { nofile: true, stats: true });
console.log(pathsWithStats);
The 'glob' package provides similar functionality for matching files using the patterns known as 'globs'. Unlike klaw-sync, which provides a list of files by walking the directory tree, glob applies pattern matching to select files. It can be used synchronously or asynchronously.
The 'readdirp' package is another Node.js module that reads directories recursively. It streams entry information and can be a more memory-efficient way to handle large directories. It is similar to klaw-sync but is built around a streaming interface.
The 'node-dir' package provides a range of directory and file reading utilities. It can read files recursively and synchronously like klaw-sync, but it also offers additional utilities for reading files asynchronously, reading the contents of files, and more.
klaw-sync
is a Node.js recursive and fast file system walker, which is the synchronous counterpart of klaw. It lists all files and directories inside a directory recursively and returns an array of objects that each object has two properties: path
and stats
. path
is the full path of the file or directory and stats
is an instance of fs.Stats.
npm i klaw-sync
directory
<String>
options
<Object>
(optional) all options are false
by default
nodir
<Boolean>
nofile
<Boolean>
depthLimit
: <Number>
-1
for unlimited.fs
: <Object>
fs
, useful when mocking fs
object.filter
<Function>
fn({path: '', stats: {}})
and returns true to include or false to exclude the item.traverseAll
<Boolean>
filter
option. (When set to true
, traverseAll
produces similar behavior to the default behavior prior to v4.0.0. The current default of traverseAll: false
is equivalent to the old noRecurseOnFailedFilter: true
).<Array<Object>>
[{path: '', stats: {}}]
const klawSync = require('klaw-sync')
const paths = klawSync('/some/dir')
// paths = [{path: '/some/dir/dir1', stats: {}}, {path: '/some/dir/file1', stats: {}}]
catch error
const klawSync = require('klaw-sync')
let paths
try {
paths = klawSync('/some/dir')
} catch (er) {
console.error(er)
}
console.dir(paths)
files only
const klawSync = require('klaw-sync')
const files = klawSync('/some/dir', {nodir: true})
// files = [{path: '/some/dir/file1', stats: {}}, {path: '/some/dir/file2', stats: {}}]
directories only
const klawSync = require('klaw-sync')
const dirs = klawSync('/some/dir', {nofile: true})
// dirs = [{path: '/some/dir/dir1', stats: {}}, {path: '/some/dir/dir2', stats: {}}]
ignore hidden directories
const path = require('path')
const klawSync = require('klaw-sync')
const filterFn = item => {
const basename = path.basename(item.path)
return basename === '.' || basename[0] !== '.'
}
const paths = klawSync('/some/dir', { filter: filterFn})
filter based on stats
Here traverseAll
option is required since we still want to read all directories even if they don't pass the filter
function, to see if their contents do pass the filter
function.
const klawSync = require('klaw-sync')
const refTime = new Date(2017, 3, 24).getTime()
const filterFn = item => item.stats.mtime.getTime() > refTime
const paths = klawSync('/some/dir', { filter: filterFn })
lint: npm run lint
unit test: npm run unit
lint & unit: npm test
benchmark: npm run benchmark
Running some benchmark tests on these modules:
klaw-sync
(as of Jan 25, 2017) klaw-sync
is the fastest module!
Running benchmark tests..
root dir length: 1110
walk-sync x 139 ops/sec ±2.48% (76 runs sampled)
klaw-sync x 163 ops/sec ±1.20% (80 runs sampled)
Fastest is klaw-sync
root dir length: 11110
walk-sync x 13.23 ops/sec ±1.10% (37 runs sampled)
klaw-sync x 15.10 ops/sec ±1.06% (41 runs sampled)
Fastest is klaw-sync
root dir length: 111110
walk-sync x 1.17 ops/sec ±2.06% (7 runs sampled)
klaw-sync x 1.25 ops/sec ±2.10% (8 runs sampled)
Fastest is klaw-sync
Special thanks to:
for their contribution and support.
Licensed under MIT
FAQs
Recursive, synchronous, and fast file system walker
We found that klaw-sync demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
Security News
NVD’s backlog surpasses 20,000 CVEs as analysis slows and NIST announces new system updates to address ongoing delays.
Security News
Research
A malicious npm package disguised as a WhatsApp client is exploiting authentication flows with a remote kill switch to exfiltrate data and destroy files.