
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
markdown-escapes
Advanced tools
List of escapable characters in markdown.
This package is ESM only: Node 12+ is needed to use it and it must be imported
instead of required.
npm:
npm install markdown-escapes
import {markdownEscapes} from 'markdown-escapes'
console.log(markdownEscapes) //=> ['!', '"', '#', /* … */ '|', '}', '~']
This package exports the following identifiers: markdownEscapes.
There is no default export.
markdownEscapesList of escapable characters (string[]) in CommonMark and GFM (they’re the
same).
markdown-it is a powerful Markdown parser and renderer. While it focuses more on converting Markdown into HTML, it also offers a range of plugins that can handle escaping and unescaping of Markdown content, among other functionalities. Compared to markdown-escapes, markdown-it provides a broader set of features for working with Markdown, making it suitable for more complex Markdown processing tasks.
remarkable is another comprehensive Markdown parser that supports a wide range of Markdown extensions and features. It includes capabilities for escaping special characters in Markdown, similar to markdown-escapes, but also offers a full suite of Markdown processing tools, including parsing, rendering, and plugin support. This makes remarkable a more versatile option for users who need more than just character escaping.
FAQs
Legacy list of escapable characters in markdown
The npm package markdown-escapes receives a total of 736,980 weekly downloads. As such, markdown-escapes popularity was classified as popular.
We found that markdown-escapes demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.