Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
github.com/algolia/demo-textarea-autocomplete
This is a sample project implementing a dropdown search (triggered by the @
character) directly inside a textarea using Algolia.
You can try the live demos or follow the guide to build your own.
@mention
feature where users can reference people, places, resources, ...We build 4 variations on the same principle, with increasing complexity. Feel free to have a look at the code or read the guide to see how to build your own.
Basic autocomplete (source code) | With picture (source code) |
---|---|
Rich HTML textarea (source code) | With picture (source code) |
---|---|
The dataset is coming from themoviedb.org and contains the list of the 500 more popular actors.
The demo website can be deployed on GitHub pages by running npm run deploy
.
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.