
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Library for better handling WebSocket interactions and waiting for response messages
Simplifies communication over WebSocket.
Serialization/Deserialization out of the box
More structured way to exchange messages (separates type
from payload
)
waitSocket.sendMessage('MESSAGE_TYPE', { somePayload: 'example' });
Convenient way to handle incoming messages:
waitSocket.on('MESSAGE_TYPE', (payload) => doSomething(payload));
Ability to use a request/response paradigm with WebSockets (mechanism described below):
const { payload } = await waitSocket.sendRequest('MESSAGE_TYPE', requestPayload);
Ability to add interceptors to modify incoming and outgoing messages:
waitSocket.interceptors.incoming.use((messageObject) => {
console.log('Let\'s see what we have received', messageObject);
// And modify the object
return {
...messageObject,
something: 'new',
};
});
Flexible message format customization
Fully TypeScript
npm i waitsocket
or
yarn add waitsocket
import WaitSocket from 'waitsocket';
const waitSocket = new WaitSocket('ws://my.websocket.server:9000');
Or you can use it with your own instance of WebSocket, and even with some extends like RobustWebSocket:
const ws = new RobustWebSocket('ws://my.websocket.server:9000');
const waitSocket = new WaitSocket(ws);
You can define JSONSchema for each type of your incoming and outgoing messages. For incoming messages, validation process original deserialized message (before any interceptors). For outgoing messages, validation process resulting message (after all interceptors, but before serialization, of course).
this.waitSocket.addIncomingJSONSchema('MESSAGE_TYPE', jsonSchemaObject);
If you wish to use your own message format, you can do it by extending WaitSocket class and overriding these functions, responsible for message construction and parsing:
getType(messageObject: MessageType): string
- Returns message type.getPayload(messageObject: MessageType): any
- Returns message payload.getRequestId(messageObject: MessageType): string
- Returns message requestId meta data.getMessageObject(type: string, payload?: any, requestId?: string): MessageType;
- Returns message object with type, payload and requestId in it.Example (use body
parameter instead of payload
):
class myWaitSocket extends AbstractWaitSocket<MyMessageType> {
protected getMessageObject(type: string, payload?: any, requestId?: string) {
const result: DefaultMessageType = { type };
if (payload) {
result.body = payload;
}
if (requestId) {
result.meta = { requestId };
}
return result;
}
public getPayload(messageObject: PlainObject) {
return messageObject.body;
}
}
FAQs
Library for better handling WebSocket interactions and waiting for response messages
The npm package waitsocket receives a total of 0 weekly downloads. As such, waitsocket popularity was classified as not popular.
We found that waitsocket demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.