
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
node-red-node-msgpack
Advanced tools
A Node-RED node to pack and unpack objects to msgpack format buffers.
Run the following command in your Node-RED user directory - typically ~/.node-red
npm install node-red-node-msgpack
Version 1.0.0 - move to msgpack-lite library (more supported and faster) - This uses the more recent msgpack specification so please ensure all your endpoints are also using the latest spec.
Uses the msgpack-lite npm to pack and unpack msg.payload objects to msgpack format buffers.
Note: this node does not currently encode raw buffer types.
It will automatically try to decode any buffer received, and may not cause an error.
If the input is NOT a buffer it converts it into a msgpack buffer.
If the input is a msgpack buffer it converts it back to the original type.
FAQs
A Node-RED node to pack and unpack objects to msgpack format
The npm package node-red-node-msgpack receives a total of 253 weekly downloads. As such, node-red-node-msgpack popularity was classified as not popular.
We found that node-red-node-msgpack demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.