
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@thednp/event-listener
Advanced tools
🚅 Modern event listener for efficient web applications based on subscribe-publish pattern.
A TypeScript sourced event listener for efficient applications based on the subscribe-publish pattern, around 700 bytes when minified and packs a surprising amount of power.
globalListener
to call them all at once when event is triggered;once
, meaning that when the option is true
, the listener is automatically un-subscribed and detached from target;pnpm install @thednp/event-listener
yarn add @thednp/event-listener
npm install @thednp/event-listener
deno add npm:@thednp/event-listener@latest
<script src="https://cdn.jsdelivr.net/npm/@thednp/event-listener/dist/event-listener.js"></script>
import * as Listener from '@thednp/event-listener';
// execute a listener once
Listener.on(document, 'DOMContentLoaded', () => {
console.log('document is now loaded');
},
{ once: true },
);
// add a listener with `useCapture: false`
function handleMyClick(e: Listener.NativeEvent) {
if (e.target.tagName === 'button') {
e.preventDefault();
e.stopImmediatePropagation();
}
console.log('do something else instead');
}
Listener.on(document, 'click', handleMyClick, false);
// remove a listener, `EventListener` will get listener options from registry
Listener.off(document, 'click', handleMyClick);
// add listener to `window`, this listener has no name and cannot be removed
Listener.on(window, 'scroll', () => console.log(window.scrollY));
Since we're implementing Map
, you can make use of its prototype to access registry:
// get element listener registry
const documentClickListeners = Listener.registry['click'].get(document);
// returns
Map(1) {
Entries => [
0: {
key: handleMyClick() // listener
value: false // listener options
}
],
size: 1, // size of the Map
prototype: [Prototype(Map)]
}
// check if element has listener
if (documentClickListeners && documentClickListeners.has(handleMyClick)) {
// do something about it
}
// check if a listener is the one you're looking for
if (documentClickListeners) {
const [eventListener] = documentClickListeners;
if (eventListener === handleMyClick) {
// do something about it
}
}
// get listener options
const myListenerOptions = documentClickListeners && documentClickListeners.get(handleMyClick);
// returns false, which is the `useCapture` option value added for `handleMyClick`
You can also make use of the types for more consistent code:
import { on, FocusEventHandler } from '@thednp/event-listener';
const handleMyFocus: FocusEventHandler<HTMLInputElement> = (e) => {
console.log(e)
}
const myInput = document.querySelector('input') || document.createElement('input');
on(myInput, 'focus', handleMyFocus);
For more advanced use, check out the demo, showcasing the EventListener usage with a demo component.
npm install
or npm update
, takes a few minutes to download the Electron browser;npm run test-ui
to open the browser mode testing OR npm run test
to run the tests in headless mode.EventListener is released under the MIT License.
FAQs
🚅 Modern event listener for efficient web applications based on subscribe-publish pattern.
We found that @thednp/event-listener demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.