
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
Useful when you need to cache something and limit memory usage.
See the algorithm section for implementation details.
npm install quick-lru
import QuickLRU from 'quick-lru';
const lru = new QuickLRU({maxSize: 1000});
lru.set('🦄', '🌈');
lru.has('🦄');
//=> true
lru.get('🦄');
//=> '🌈'
Returns a new instance.
It's a Map subclass.
Type: object
Required
Type: number
The target maximum number of items before evicting the least recently used items.
[!NOTE] This package uses an algorithm which maintains between
maxSizeand2 × maxSizeitems for performance reasons. The cache may temporarily contain up to twice the specified size due to the dual-cache design that avoids expensive delete operations.
Type: number
Default: Infinity
The maximum number of milliseconds an item should remain in the cache.
By default, maxAge will be Infinity, which means that items will never expire.
Lazy expiration occurs upon the next write or read call.
Individual expiration of an item can be specified by the set(key, value, options) method.
Optional
Type: (key, value) => void
Called right before an item is evicted from the cache due to LRU pressure, TTL expiration, or manual eviction via evict().
Useful for side effects or for items like object URLs that need explicit cleanup (revokeObjectURL).
[!NOTE] This callback is not called for manual removals via
delete()orclear(). It fires for automatic evictions and manual evictions viaevict().
The instance is an Iterable of [key, value] pairs so you can use it directly in a for…of loop.
Both key and value can be of any type.
Set an item. Returns the instance.
Individual expiration of an item can be specified with the maxAge option. If not specified, the global maxAge value will be used in case it is specified in the constructor; otherwise, the item will never expire.
Get an item.
Check if an item exists.
Get an item without marking it as recently used.
Delete an item.
Returns true if the item is removed or false if the item doesn't exist.
Delete all items.
Get the remaining time to live (in milliseconds) for the given item, or undefined if the item is not in the cache.
Infinity if the item has no expiration (maxAge not set for the item and no global maxAge).Update the maxSize, discarding items as necessary. Insertion order is mostly preserved, though this is not a strong guarantee.
Useful for on-the-fly tuning of cache sizes in live systems.
Evict the least recently used items from the cache.
The count parameter specifies how many items to evict. Defaults to 1.
It will always keep at least one item in the cache.
import QuickLRU from 'quick-lru';
const lru = new QuickLRU({maxSize: 10});
lru.set('a', 1);
lru.set('b', 2);
lru.set('c', 3);
lru.evict(2); // Evicts 'a' and 'b'
console.log(lru.has('a'));
//=> false
console.log(lru.has('c'));
//=> true
Iterable for all the keys.
Iterable for all the values.
Iterable for all entries, starting with the oldest (ascending in recency).
Iterable for all entries, starting with the newest (descending in recency).
Iterable for all entries, starting with the oldest (ascending in recency).
This method exists for Map compatibility. Prefer .entriesAscending() instead.
Loop over entries calling the callbackFunction for each entry (ascending in recency).
This method exists for Map compatibility. Prefer .entriesAscending() instead.
The stored item count.
The set max size.
The set max age.
This library implements a variant of the hashlru algorithm using JavaScript's Map for broader key type support.
The algorithm uses a dual-cache approach with two Map objects:
On set() operations:
maxSize, promote it to become the old cache and create a fresh new cacheOn get() operations:
delete operations that can cause performance issues in JavaScript enginesmaxSize and 2 × maxSize items temporarilyChoose this implementation when:
Consider alternatives when:
maxSize items)lru-cache is another popular LRU cache implementation. It offers a similar set of features to quick-lru, such as set, get, eviction of old items, and item deletion. However, it has additional features like item expiration times, which quick-lru does not support.
node-cache is a simple caching module with set, get, and delete methods, similar to quick-lru. It supports TTL (time to live) for cache items and can be used as a plain key-value store. It is not strictly an LRU cache, but it provides similar caching capabilities.
tiny-lru is a minimal LRU cache implementation that is small in size. It provides basic LRU caching functionality like quick-lru but is designed to have a smaller footprint, making it suitable for environments where package size is a concern.
FAQs
Simple “Least Recently Used” (LRU) cache
The npm package quick-lru receives a total of 21,758,098 weekly downloads. As such, quick-lru popularity was classified as popular.
We found that quick-lru demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.