
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
lz4-wasm
Extremely fast compression(200MB/s Firefox, 350Mb/s Chrome) and decompression(600MB/s Firefox, 1400Mb/s Chrome) in the browser or nodejs using wasm.
Built with Rust
The wasm module exposes two function compress and decompress. Both accept and return UInt8Array. Internally the lz4 block api is used, the length of the original input is prepended in 32-bit little endian.
import * as wasm from "lz4-wasm";
// use TextEncoder to get bytes (UInt8Array) from string
var enc = new TextEncoder();
const compressed = wasm.compress(enc.encode("compress this text, compress this text pls. thx. thx. thx. thx. thx"));
const original = wasm.decompress(compressed);
var dec = new TextDecoder("utf-8");
alert(dec.decode(original))
See https://github.com/PSeitz/lz4_flex/tree/master/lz4-wasm/example_project for usage and benchmark.
Build. This will optimize usage for inside a bundler like webpack.
RUST_LOG=info wasm-pack build --release
Due to a long standing bug in wasm-pack 0.9.1, manually add these files to pkg/package.json.
"lz4_wasm_bg.wasm.d.ts",
"lz4_wasm_bg.js",
RUST_LOG=info wasm-pack publish
set name in Cargo toml to
name = "lz4-wasm-nodejs"
Build for nodejs
RUST_LOG=info wasm-pack build --release -t nodejs
RUST_LOG=info wasm-pack publish
FAQs
High Performance lz4 wasm implementation
The npm package lz4-wasm receives a total of 351 weekly downloads. As such, lz4-wasm popularity was classified as not popular.
We found that lz4-wasm demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.