Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@ledzz/natuerlich
Advanced tools
WebXR Interaction for Three.js
This library builds on Three.js (open-source WebGL library) and WebXR (Web Standard for Augmented and Virtual Reality) to deliver composable and extensible interactions for immersive experiences .
We provide bindings to react-three/fiber, enabling a familiar Developer Experience for react developers.
npm install @coconut-xr/natuerlich
Placing Objects - 3D Models from Quaternius
Rag Doll Physics - based on R3F Example
Getting Started - barebones WebXR, Hands, and Controllers
Interaction with Objects - build interactions with objects
Interaction with Koestlich - build interactive 3D UIs
Teleport - building a teleport interaction
Poses - detecting and generating hand poses
Layers - high quality content using WebXR layers
Anchors - spatial anchors using WebXR anchors
Tracked Planes - tracked room planes using WebXR planes
Head Up Display - placing content in front of the user's camera
Custom Input Sources - building custom interactive hands and controllers
Tracked Images - image marker tracking using WebXR Image Tracking
Guards - conditional rendering using guards
Use XR - accessing the raw XR state
Configuration - configurating foveation, frameRate, referenceSpace, and frameBufferScaling
This library is only possible because of the great efforts from the Immersive Web Community Group and Immersive Web Working Group at the W3C, the Three.js team, and the react-three-fiber team. This work is inspired by existing libraries, such as react-xr and handy-work.
natuerlich is funded by Coconut Capital
FAQs
webxr interaction for three.js
The npm package @ledzz/natuerlich receives a total of 0 weekly downloads. As such, @ledzz/natuerlich popularity was classified as not popular.
We found that @ledzz/natuerlich demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.