
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
Break up a stream and reassemble it so that each line is a chunk.
split2 is inspired by @dominictarr split module,
and it is totally API compatible with it.
However, it is based on Node.js core Transform via readable-stream
matcher may be a String, or a RegExp. Example, read every line in a file ...
fs.createReadStream(file)
.pipe(split2())
.on('data', function (line) {
//each chunk now is a separate line!
})
split takes the same arguments as string.split except it defaults to '/\r?\n/', and the optional limit paremeter is ignored.
String#split
split takes an optional options object on it's third argument, which
is directly passed as a
Transform
option.
Additionally, the .maxLength option is implemented, which will make the split stream throw an error
if the buffer size exceeds .maxLength.
Calling .destroy will make the stream emit close. Use this to perform cleanup logic
var splitFile = function(filename) {
var file = fs.createReadStream(filename)
return file
.pipe(split2())
.on('close', function() {
// destroy the file stream in case the split stream was destroyed
file.destroy()
})
}
var stream = splitFile('my-file.txt')
stream.destroy() // will destroy the input file stream
split2 accepts a function which transforms each line.
fs.createReadStream(file)
.pipe(split2(JSON.parse))
.on('data', function (obj) {
//each chunk now is a js object
})
However, in @dominictarr split the mapper
is wrapped in a try-catch, while here it is not: if your parsing logic can throw, wrap it yourself.
$ node bench.js
benchSplit*10000: 1484.983ms
benchBinarySplit*10000: 1484.080ms
benchSplit*10000: 1407.334ms
benchBinarySplit*10000: 1500.281ms
Benchmark taken on Node 8.11.3, on a Macbook i5 2018.
Copyright (c) 2014-2018, Matteo Collina hello@matteocollina.com
Permission to use, copy, modify, and/or distribute this software for any purpose with or without fee is hereby granted, provided that the above copyright notice and this permission notice appear in all copies.
THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
The byline package offers similar functionality to split2 by providing a simple way to read lines from a stream. However, it focuses more on simplicity and ease of use, potentially at the cost of some of the more advanced features and customizations offered by split2.
While not an npm package but a core Node.js module, readline provides functionality to read data from a readable stream, such as the process.stdin, one line at a time. It's more complex and versatile than split2, offering more control over the input and output streams, but it might be overkill for simple line-splitting tasks.
Though not exclusively for splitting streams into lines, through2 is a tiny wrapper around Node streams.Transform that makes it easier to create transform streams. It can be used in combination with other methods to achieve similar functionality to split2, offering a more flexible but potentially more complex solution.
FAQs
split a Text Stream into a Line Stream, using Stream 3
The npm package split2 receives a total of 15,646,347 weekly downloads. As such, split2 popularity was classified as popular.
We found that split2 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.