
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@kreativekorna/justui
Advanced tools
Shared design system for the just* app family — theme tokens, six built-in themes (GitHub, Espresso, Catppuccin Mocha, Gruvbox, Nord, Solarized), a no-flash boot script, and per-framework component adapters (Astro today; React/Vue next).
Shared design system for the just* app family — theme tokens, six built-in themes (GitHub, Espresso, Catppuccin Mocha, Gruvbox, Nord, Solarized), a no-flash boot script, ready-made Astro components, and a Tailwind preset.
See STYLE_GUIDE.md for the full design spec.
pnpm add @kreativekorna/justui
Peers your app needs separately:
pnpm add @fontsource-variable/geist @fontsource-variable/geist-mono tailwindcss
// tailwind.config.mjs
import justuiPreset from '@kreativekorna/justui/tailwind-preset';
export default {
presets: [justuiPreset],
content: [
'./src/**/*.{astro,html,js,ts,jsx,tsx,md,mdx}',
// Include the package's components so Tailwind generates classes
// used inside Button.astro / ThemeToggle.astro.
'./node_modules/@kreativekorna/justui/src/**/*.{astro,js,ts}',
],
};
/* src/styles/global.css */
@import "@kreativekorna/justui/tokens.css";
@tailwind base;
@tailwind components;
@tailwind utilities;
---
// src/layouts/Layout.astro
import '@fontsource-variable/geist';
import '@fontsource-variable/geist-mono';
import '../styles/global.css';
---
<!doctype html>
<html lang="en">
<head>
<!-- Runs before <body> renders so the right palette paints first. -->
<script>
import { bootTheme } from '@kreativekorna/justui/boot';
bootTheme({ keyPrefix: 'myapp' });
</script>
</head>
<body><slot /></body>
</html>
---
import ThemeToggle from '@kreativekorna/justui/components/ThemeToggle.astro';
---
<ThemeToggle />
The floating button at bottom-right opens a panel with a mode toggle (light/dark) + all six themes. State persists to myapp.theme.id / myapp.theme.mode.
| Export | Purpose |
|---|---|
@kreativekorna/justui | BUILT_IN_THEMES, DEFAULT_THEME_ID, VAR_MAP, bootTheme |
@kreativekorna/justui/boot | Just bootTheme — small import if you only want this |
@kreativekorna/justui/themes | Just the theme catalog |
@kreativekorna/justui/tokens.css | :root fallback (Espresso dark) |
@kreativekorna/justui/tailwind-preset | Tailwind config preset |
@kreativekorna/justui/components/Button.astro | Primary / secondary button |
@kreativekorna/justui/components/ThemeToggle.astro | Floating theme picker |
Each just* app should call bootTheme({ keyPrefix: '<appname>' }) so theme state doesn't collide on shared origins. The ThemeToggle reads the prefix from the global window.__JUSTUI__ that bootTheme() stamps, so the same component works in every app without per-app config.
If you want themes to be shared across apps on the same origin (so picking Gruvbox in one carries to the other), use the default keyPrefix: 'justui' everywhere.
MIT
FAQs
Shared design system for the just* app family — theme tokens, six built-in themes (GitHub, Espresso, Catppuccin Mocha, Gruvbox, Nord, Solarized), a no-flash boot script, and per-framework component adapters (Astro today; React/Vue next).
We found that @kreativekorna/justui demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.