
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
lru-cache-ext
Advanced tools
Thin wrapper around lru-cache with extended functionality.
Install with npm:
$ npm install --save lru-cache-ext
Please refer to lru-cache.
Some additional, non-invasive functionality is added.
Only when the key is not present in cache (or has expired), valueFn
is called and placed into cache.
The cached value is returned when it becomes available (important in the case where valueFn
is async).
The cache is left empty if an error is thrown at any point in valueFn
(even asynchronous).
Useful when multiple async operation need to access the same async information.
Similar to "memoize", when key is not present (or has expired), valueFn
is called and placed into the cache.
Cached value is returned from the function.
valueFn
can be a synchronous or asynchronous function.
If valueFn
is an asynchronous function and an error is thrown asynchronously, the cache is not invalidated.
FAQs
Thin wrapper around lru-cache with extended functionality.
The npm package lru-cache-ext receives a total of 714 weekly downloads. As such, lru-cache-ext popularity was classified as not popular.
We found that lru-cache-ext demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.