
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
rescript-schema
Advanced tools
🧬 The fastest parser in the entire JavaScript ecosystem with a focus on small bundle size and top-notch DX
The fastest parser in the entire JavaScript ecosystem with a focus on small bundle size and top-notch DX.
⚠️ Be aware that rescript-schema uses
evalfor parsing. It's usually fine but might not work in some environments like Cloudflare Workers or third-party scripts used on pages with the script-src header.
Highlights:
Also, you can use rescript-schema as a building block for your tools. And there are many existing ones:
Instead of relying on a few large functions with many methods, rescript-schema follows Valibot's approach, where API design and source code is based on many small and independent functions, each with just a single task. This modular design has several advantages.
For example, this allows a bundler to use the import statements to remove code that is not needed. This way, only the code that is actually used gets into your production build. This can reduce the bundle size by up to 2 times compared to Zod.
Besides the individual bundle size, the overall size of the library is also significantly smaller.
At the same time rescript-schema is the fastest composable validation library in the entire JavaScript ecosystem. This is achieved because of the JIT approach when an ultra optimized validator is created using eval.
| rescript-schema@9.2.2 | Zod@3.24.1 | Valibot@0.42.1 | ArkType@2.0.4 | |
|---|---|---|---|---|
| Total size (minified + gzipped) | 11 kB | 14.8 kB | 10.5 kB | 40.8 kB |
| Example size (minified + gzipped) | 4.45 kB | 13.5 kB | 1.22 kB | 40.7 kB |
| Parse with the same schema | 93,491 ops/ms | 1,191 ops/ms | 3,540 ops/ms | 84,772 ops/ms |
| Create schema & parse once | 166 ops/ms | 93 ops/ms | 2,302 ops/ms | 13 ops/ms |
| Eval-free | ❌ | ✅ | ✅ | ❓ |
| Codegen-free (Doesn't need compiler) | ✅ | ✅ | ✅ | ✅ |
| Ecosystem | ⭐️⭐️ | ⭐️⭐️⭐️⭐️⭐️ | ⭐️⭐️⭐️ | ⭐️⭐️ |
FAQs
🧬 The fastest parser in the entire JavaScript ecosystem with a focus on small bundle size and top-notch DX
We found that rescript-schema demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.