
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
nested-obj
Advanced tools
nested-obj is a simple and lightweight JavaScript utility library for safely accessing and modifying nested properties in objects using string paths.
npm install nested-obj
Retrieve a nested property value from an object.
import objectPath from 'nested-obj';
const obj = {
user: {
name: 'John Doe',
address: {
street: '123 Main St',
city: 'Anytown'
}
}
};
const userName = objectPath.get(obj, 'user.name');
console.log(userName); // 'John Doe'
Set a value at a specific path in an object. If any part of the path does not exist, it will be created.
objectPath.set(obj, 'user.address.zip', '12345');
console.log(obj.user.address.zip); // '12345'
Check if a path exists within an object.
const hasCity = objectPath.has(obj, 'user.address.city');
console.log(hasCity); // true
To run tests, execute the following command:
npm test
or for continuous
npm test:watch
git clone https://github.com/constructive-io/dev-utils.git
cd dev-utils
pnpm install
pnpm build
cd packages/<packagename>
pnpm test:watch
Built for developers, with developers.
👉 https://launchql.com | https://hyperweb.io
AS DESCRIBED IN THE LICENSES, THE SOFTWARE IS PROVIDED "AS IS", AT YOUR OWN RISK, AND WITHOUT WARRANTIES OF ANY KIND.
No developer or entity involved in creating this software will be liable for any claims or damages whatsoever associated with your use, inability to use, or your interaction with other users of the code, including any direct, indirect, incidental, special, exemplary, punitive or consequential damages, or loss of profits, cryptocurrencies, tokens, or anything else of value.
FAQs
Safely access and modify nested object properties using string paths
The npm package nested-obj receives a total of 17,675 weekly downloads. As such, nested-obj popularity was classified as popular.
We found that nested-obj demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.