Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
The tedious npm package is a pure JavaScript, non-blocking, TDS (Tabular Data Stream) protocol implementation used to interact with Microsoft SQL Server databases. It allows for the execution of SQL queries, parameterized statements, and stored procedures, making it a versatile tool for database operations within Node.js applications.
Executing SQL Queries
This feature allows for the execution of SQL queries against a SQL Server database. The code sample demonstrates how to connect to a database and execute a simple SELECT query.
const Connection = require('tedious').Connection;
const Request = require('tedious').Request;
const config = {
server: 'your_server.database.windows.net',
authentication: {
type: 'default',
options: {
userName: 'your_username',
password: 'your_password',
}
},
options: {
database: 'your_database',
encrypt: true
}
};
const connection = new Connection(config);
connection.on('connect', function(err) {
if (err) {
console.log('Error:', err);
} else {
console.log('Connected!');
executeStatement();
}
});
function executeStatement() {
const request = new Request(
"SELECT * FROM your_table;",
function(err, rowCount, rows) {
console.log(rowCount + ' row(s) returned');
}
);
request.on('row', function(columns) {
columns.forEach(function(column) {
console.log('%s %s', column.metadata.colName, column.value);
});
});
connection.execSql(request);
}
Parameterized Statements
This feature supports the execution of parameterized statements, enhancing security by preventing SQL injection. The code sample shows how to execute a query with a parameter.
const Request = require('tedious').Request;
const TYPES = require('tedious').TYPES;
function executeParameterizedStatement() {
const request = new Request(
"SELECT * FROM your_table WHERE your_column = @value;",
function(err) {
if (err) {
console.log('Error:', err);
}
}
);
request.addParameter('value', TYPES.Int, 123);
request.on('row', function(columns) {
columns.forEach(function(column) {
console.log('%s %s', column.metadata.colName, column.value);
});
});
connection.execSql(request);
}
Executing Stored Procedures
This feature allows for the execution of stored procedures within the database. The code sample demonstrates calling a stored procedure and retrieving an output parameter.
const Request = require('tedious').Request;
function executeStoredProcedure() {
const request = new Request(
'your_stored_procedure',
function(err) {
if (err) {
console.log('Error:', err);
}
}
);
request.addOutputParameter('output_parameter', TYPES.VarChar);
request.on('returnValue', function(parameterName, value, metadata) {
console.log(parameterName + ' : ' + value);
});
connection.callProcedure(request);
}
The mssql package is another popular choice for interacting with SQL Server databases from Node.js. It provides a higher-level abstraction over tedious, offering a simpler API for executing queries, parameterized statements, and transactions. While tedious offers more direct control over the TDS protocol, mssql simplifies many common tasks, making it a more accessible option for some developers.
node-mssql is an alias or a closely related package to mssql, providing similar functionalities. It's often used interchangeably in discussions and documentation, but primarily, 'mssql' is the package name used for installation and implementation in projects.
Sequelize is a promise-based Node.js ORM for Postgres, MySQL, MariaDB, SQLite, and Microsoft SQL Server. It features solid transaction support, relations, eager and lazy loading, read replication, and more. While tedious is focused on SQL Server and provides a low-level API for database operations, Sequelize offers an ORM layer, making it easier to work with different databases using a unified API. However, this abstraction comes at the cost of direct control over SQL execution.
Tedious is a pure-Javascript implementation of the TDS protocol, which is used to interact with instances of Microsoft's SQL Server. It is intended to be a fairly slim implementation of the protocol, with not too much additional functionality.
NOTE: New columns are nullable by default as of version 1.11.0
Previous behavior can be restored using config.options.enableAnsiNullDefault = false
. See pull request 230.
NOTE: Default login behavior has changed slightly as of version 1.2
See the changelog for version history.
Node.js is a prerequisite for installing tedious. Once you have installed Node.js, installing tedious is simple:
npm install tedious
More documentation and code samples are available at tediousjs.github.io/tedious/
Tedious is simply derived from a fast, slightly garbled, pronunciation of the letters T, D and S.
We'd like to learn more about how you use tedious:
We welcome contributions from the community. Feel free to checkout the code and submit pull requests.
Copyright (c) 2010-2021 Mike D Pilsbury
The MIT License
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
FAQs
A TDS driver, for connecting to MS SQLServer databases.
The npm package tedious receives a total of 1,385,880 weekly downloads. As such, tedious popularity was classified as popular.
We found that tedious demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 8 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.