
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
regenerator-runtime
Advanced tools
Runtime for Regenerator-compiled generator and async functions.
Standalone runtime for
Regenerator-compiled generator
and async functions.
To import the runtime as a module (recommended), either of the following import styles will work:
// CommonJS
const regeneratorRuntime = require("regenerator-runtime");
// ECMAScript 2015
import regeneratorRuntime from "regenerator-runtime";
To ensure that regeneratorRuntime is defined globally, either of the
following styles will work:
// CommonJS
require("regenerator-runtime/runtime");
// ECMAScript 2015
import "regenerator-runtime/runtime.js";
To get the absolute file system path of runtime.js, evaluate the
following expression:
require("regenerator-runtime/path").path
Babel-polyfill includes regenerator-runtime along with a full ES2015+ environment polyfill. It is more comprehensive but also larger in size compared to regenerator-runtime, which focuses only on generator and async function support.
Core-js is a modular standard library for JavaScript, which includes polyfills for ECMAScript features. It provides similar functionality to regenerator-runtime but also includes polyfills for other features such as Promises, Symbols, Collections, Iterators, and more.
While not providing generator or async function support, es6-promise is a lightweight library that offers a polyfill for Promises, which are often used in conjunction with async/await syntax. It is more focused compared to regenerator-runtime, which provides broader support for ES2015+ features.
FAQs
Runtime for Regenerator-compiled generator and async functions.
The npm package regenerator-runtime receives a total of 23,433,851 weekly downloads. As such, regenerator-runtime popularity was classified as popular.
We found that regenerator-runtime demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.