
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Node.js's util module for all engines.
This implements the Node.js util module for environments that do not have it, like browsers.
You usually do not have to install util yourself. If your code runs in Node.js, util is built in. If your code runs in the browser, bundlers like browserify or webpack (up to version 4 -- see this documentation for how to include polyfills like util in webpack 5+) also include the util module.
But if none of those apply, with npm do:
npm install util
var util = require('util')
var EventEmitter = require('events')
function MyClass() { EventEmitter.call(this) }
util.inherits(MyClass, EventEmitter)
The util module uses ES5 features. If you need to support very old browsers like IE8, use a shim like es5-shim. You need both the shim and the sham versions of es5-shim.
To use util.promisify and util.callbackify, Promises must already be available. If you need to support browsers like IE11 that do not support Promises, use a shim. es6-promise is a popular one but there are many others available on npm.
See the Node.js util docs. util currently supports the Node 8 LTS API. However, some of the methods are outdated. The inspect and format methods included in this module are a lot more simple and barebones than the ones in Node.js.
PRs are very welcome! The main way to contribute to util is by porting features, bugfixes and tests from Node.js. Ideally, code contributions to this module are copy-pasted from Node.js and transpiled to ES5, rather than reimplemented from scratch. Matching the Node.js code as closely as possible makes maintenance simpler when new changes land in Node.js.
This module intends to provide exactly the same API as Node.js, so features that are not available in the core util module will not be accepted. Feature requests should instead be directed at nodejs/node and will be added to this module once they are implemented in Node.js.
If there is a difference in behaviour between Node.js's util module and this module, please open an issue!
Lodash is a utility library offering a wide range of methods for manipulating objects, arrays, strings, etc. It's more comprehensive than 'util' but doesn't include some of the Node.js-specific utilities like promisify.
Underscore.js is a utility library similar to Lodash, providing functional programming helpers without extending any built-in objects. It's less feature-rich compared to Lodash and doesn't include Node.js-specific utilities.
Chalk is a library for styling terminal strings. It doesn't offer the broad utility functions of 'util' but focuses on a specific area of string styling which 'util' doesn't cover.
Bluebird is a library focused on providing advanced features for promises, such as cancellation, progress, and long stack traces. It complements 'util' by enhancing promise functionality beyond what 'util.promisify' offers.
FAQs
Node.js's util module for all engines
The npm package util receives a total of 33,666,469 weekly downloads. As such, util popularity was classified as popular.
We found that util demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.