
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@globestudio/react
Advanced tools
Drop-in React component for embedding Globestudio dotted globes — pick a preset, drop the component, done. Works in React, Next.js, Remix, Astro, anywhere JSX renders.
Drop-in React component for embedding Globestudio dotted globes and maps. Zero deps, SSR-friendly, autocomplete on every preset.
npm install @globestudio/react
# or pnpm add @globestudio/react
# or yarn add @globestudio/react
import { Globe } from "@globestudio/react";
export default function Page() {
return (
<section>
<h1>Worldwide coverage</h1>
<Globe look="aurora" width={800} height={600} />
</section>
);
}
That's it. The component is a styled <iframe> over globestudio.app/embed, so the heavy lift (Three.js, shaders, country data) runs on the embed origin — your bundle stays a couple hundred bytes.
| Prop | Type | Default | Notes |
|---|---|---|---|
look | LookId | "halftone" | Autocomplete on every shipped preset |
width | number | string | "100%" | Numbers → pixels |
height | number | string | 480 | Numbers → pixels |
config | string | — | Pre-built share-URL payload — overrides look |
title | string | "Globestudio dotted globe" | A11y label |
className | string | — | Forwarded |
style | CSSProperties | — | Merged after border: 0 |
loading | "lazy" | "eager" | "lazy" | Off-screen embeds defer WebGL until scrolled near |
source | string | — | Tag for analytics attribution |
onLoad | (e) => void | — | Forwarded |
import { globestudio } from "@globestudio/react";
const embed = globestudio.embedUrl({ look: "vapor" });
// → "https://globestudio.app/embed?look=vapor"
const thumb = globestudio.thumbnailUrl("halftone");
// → "https://globestudio.app/looks/halftone.png"
const share = globestudio.shareUrl("eyJsb29rIjoidmFwb3IifQ");
// → "https://globestudio.app/?c=eyJsb29rIjoidmFwb3IifQ"
Use these when you need the URL but not the iframe (e.g. Next.js <Image src>, server-rendered markup, OG metadata).
The component is just JSX — renders the iframe HTML on the server, hydrates on the client without re-mounting (no client-only state, no useEffect).
// app/page.tsx (Next.js App Router)
import { Globe } from "@globestudio/react";
export default function Page() {
return <Globe look="risograph" />;
}
// Fill container
<Globe look="halftone" /> {/* width="100%", height=480 default */}
// Square in a card
<div style={{ width: 320, aspectRatio: "1 / 1" }}>
<Globe look="aurora" width="100%" height="100%" />
</div>
// Background hero
<section style={{ position: "relative", height: 520 }}>
<Globe
look="vapor"
width="100%"
height="100%"
style={{ position: "absolute", inset: 0 }}
/>
<div style={{ position: "relative", padding: 64 }}>
<h1>Hero content over the globe</h1>
</div>
</section>
The snippet on globestudio.app/integrations is what most people start with. The package adds:
look — no typos shipping to prodglobestudio.* helpers for URL building outside the iframe contextThe total surface area is one component and one helper object. Stays tiny on purpose.
MIT — see LICENSE.
FAQs
React component that embeds a Globestudio dotted globe. Works in React, Next.js, Remix, Astro and anywhere JSX renders.
The npm package @globestudio/react receives a total of 197 weekly downloads. As such, @globestudio/react popularity was classified as not popular.
We found that @globestudio/react demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.