
Research
/Security News
5 Malicious Rust Crates Posed as Time Utilities to Exfiltrate .env Files
Published late February to early March 2026, these crates impersonate timeapi.io and POST .env secrets to a threat actor-controlled lookalike domain.
@floating-ui/react-dom
Advanced tools
This is the library to use Floating UI with React DOM.
Popper.js is a popular library for managing poppers in web applications. It provides similar functionalities to @floating-ui/react-dom, such as dynamic positioning and flipping of poppers based on the viewport. However, @floating-ui/react-dom is specifically tailored for React and offers a more React-friendly API with hooks.
Tippy.js is another library focused on creating tooltips and popovers. It builds on top of Popper.js and adds an abstraction layer that includes default styling and behavior. Tippy.js is easier to use for simple tooltips and popovers but offers less low-level control compared to @floating-ui/react-dom, which is more configurable and suited for complex positioning scenarios in React applications.
FAQs
Floating UI for React DOM
The npm package @floating-ui/react-dom receives a total of 28,467,773 weekly downloads. As such, @floating-ui/react-dom popularity was classified as popular.
We found that @floating-ui/react-dom demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Published late February to early March 2026, these crates impersonate timeapi.io and POST .env secrets to a threat actor-controlled lookalike domain.

Security News
A recent burst of security disclosures in the OpenClaw project is drawing attention to how vulnerability information flows across advisory and CVE systems.

Research
/Security News
Mixed-script homoglyphs and a lookalike domain mimic imToken’s import flow to capture mnemonics and private keys.