
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
ULIDs are unique, sortable identifiers that work much in the same way as UUIDs, though with some improvements:
ULIDs also provide:
UUID can be suboptimal for many uses-cases because:
Install using NPM:
npm install ulid --save
ULID supports the following environments:
| Version | NodeJS | Browsers | React-Native | Web Workers | Edge Functions |
|---|---|---|---|---|---|
| v3 | v18+ | Yes | Yes | Yes | ? |
| v2 | v16+ | Yes | No | No | No |
Additionally, both ESM and CommonJS entrypoints are provided.
To quickly generate a ULID, you can simply import the ulid function:
import { ulid } from "ulid";
ulid(); // "01ARZ3NDEKTSV4RRFFQ69G5FAV"
You can also input a seed time which will consistently give you the same string for the time component. This is useful for migrating to ulid.
ulid(1469918176385) // "01ARYZ6S41TSV4RRFFQ69G5FAV"
To generate monotonically increasing ULIDs, create a monotonic counter with monotonicFactory.
Note that the same seed time is being passed in for this example to demonstrate its behaviour when generating multiple ULIDs within the same millisecond
import { monotonicFactory } from "ulid";
const ulid = monotonicFactory();
// Strict ordering for the same timestamp, by incrementing the least-significant random bit by 1
ulid(150000); // "000XAL6S41ACTAV9WEVGEMMVR8"
ulid(150000); // "000XAL6S41ACTAV9WEVGEMMVR9"
ulid(150000); // "000XAL6S41ACTAV9WEVGEMMVRA"
ulid(150000); // "000XAL6S41ACTAV9WEVGEMMVRB"
ulid(150000); // "000XAL6S41ACTAV9WEVGEMMVRC"
// Even if a lower timestamp is passed (or generated), it will preserve sort order
ulid(100000); // "000XAL6S41ACTAV9WEVGEMMVRD"
ulid automatically detects a suitable (cryptographically-secure) PRNG. In the browser it will use crypto.getRandomValues and on NodeJS it will use crypto.randomBytes.
Math.random (insecure)By default, ulid will not use Math.random to generate random values. You can bypass this limitation by overriding the PRNG:
const ulid = monotonicFactory(() => Math.random());
ulid(); // "01BXAVRG61YJ5YSBRM51702F6M"
You can verify if a value is a valid ULID by using isValid:
import { isValid } from "ulid";
isValid("01ARYZ6S41TSV4RRFFQ69G5FAV"); // true
isValid("01ARYZ6S41TSV4RRFFQ69G5FA"); // false
You can encode and decode ULID timestamps by using encodeTime and decodeTime respectively:
import { decodeTime } from "ulid";
decodeTime("01ARYZ6S41TSV4RRFFQ69G5FAV"); // 1469918176385
Note that while decodeTime works on full ULIDs, encodeTime encodes only the time portion of ULIDs:
import { encodeTime } from "ulid";
encodeTime(1469918176385); // "01ARYZ6S41"
Install dependencies using npm install first, and then simply run npm test to run the test suite.
ulid can be used on the command line, either via global install:
npm install -g ulid
ulid
Or via npx:
npx ulid
You can also generate multiple IDs at the same time:
ulid --count 15
You can find the full specification, as well as information regarding implementations in other languages, over at ulid/spec.
You can test ulid's performance by running npm run bench:
Simple ulid x 56,782 ops/sec ±2.50% (86 runs sampled)
ulid with timestamp x 58,574 ops/sec ±1.80% (87 runs sampled)
Done!
The uuid package is a popular library for generating UUIDs (Universally Unique Identifiers). Unlike ULIDs, UUIDs are not lexicographically sortable but are widely used for their simplicity and uniqueness. UUIDs are typically used in distributed systems where uniqueness is critical.
The nanoid package is a library for generating unique IDs with a focus on performance and small size. Nanoid IDs are not lexicographically sortable but are very fast to generate and have a smaller footprint compared to ULIDs.
The shortid package is a library for generating short, unique, non-sequential IDs. While shortid IDs are not lexicographically sortable, they are useful for cases where a shorter ID is preferred and uniqueness is still required.
FAQs
A universally-unique, lexicographically-sortable, identifier generator
The npm package ulid receives a total of 9,005,870 weekly downloads. As such, ulid popularity was classified as popular.
We found that ulid demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.