
Research
lightning PyPI Package Compromised in Supply Chain Attack
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.
A simple LRU cache supporting O(1) set, get and eviction of old keys
$ npm install lru
var LRU = require('lru');
var cache = new LRU(2),
evicted
cache.on('evict',function(data) { evicted = data });
cache.set('foo', 'bar');
cache.get('foo'); //=> bar
cache.set('foo2', 'bar2');
cache.get('foo2'); //=> bar2
cache.set('foo3', 'bar3'); // => evicted = { key: 'foo', value: 'bar' }
cache.get('foo3'); // => 'bar3'
cache.remove('foo2') // => 'bar2'
cache.remove('foo4') // => undefined
cache.length // => 1
cache.keys // => ['foo3']
cache.clear() // => it will NOT emit the 'evict' event
cache.length // => 0
cache.keys // => []
LRU( length )Create a new LRU cache that stores length elements before evicting the least recently used.
Optionally you can pass an options map with additional options:
{
max: maxElementsToStore,
maxAge: maxAgeInMilliseconds
}
If you pass maxAge items will be evicted if they are older than maxAge when you access them.
Returns: the newly created LRU cache
.lengthThe number of keys currently in the cache.
.keysArray of all the keys currently in the cache.
.set( key, value )Set the value of the key and mark the key as most recently used.
Returns: value
.get( key )Query the value of the key and mark the key as most recently used.
Returns: value of key if found; undefined otherwise.
.peek( key )Query the value of the key without marking the key as most recently used.
Returns: value of key if found; undefined otherwise.
.remove( key )Remove the value from the cache.
Returns: value of key if found; undefined otherwise.
.clear()Clear the cache. This method does NOT emit the evict event.
.on( event, callback )Respond to events. Currently only the evict event is implemented. When a key is evicted, the callback is executed with an associative array containing the evicted key: {key: key, value: value}.
A big thanks to Dusty Leary who finished the library.
MIT
FAQs
A simple O(1) LRU cache
The npm package lru receives a total of 49,106 weekly downloads. As such, lru popularity was classified as popular.
We found that lru demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.