
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
autosize-input
Advanced tools
Effortless, dynamic-width text boxes in vanilla JavaScript.
placeholder
attributemin-width
based on the element’s initial content<input type="text" id="foo" value="Nice">
<input type="text" id="bar" placeholder="People">
<input type="text" id="baz" placeholder="Matter">
const autosizeInput = require('autosize-input')
autosizeInput(document.querySelector('#foo'))
autosizeInput(document.querySelector('#bar'))
autosizeInput(document.querySelector('#baz'), { minWidth: true })
const autosizeInput = require('autosize-input')
element
is a text input
element, and options
is an object literal.
element
.options.minWidth
to true
. This will give the element
a min-width
that fits it initial contents (ie. either the element’s intial value
, or its placeholder
).See Usage.
div
element, assigned the same styles as the text box, is used to calculate the correct width to assign to the text box. This width is recomputed and assigned to the text box on every input
event.div
is shared amongst all the “autosized” text boxes on the page.Install via yarn:
$ yarn add autosize-input
Or npm:
$ npm install --save autosize-input
To test manually, in the browser:
$ yarn start
To run the programmatic tests:
$ yarn test
This module was written because I needed a standalone, lightweight solution to this rather UI problem.
FAQs
Effortless, dynamic-width text boxes in vanilla JavaScript.
The npm package autosize-input receives a total of 9,462 weekly downloads. As such, autosize-input popularity was classified as popular.
We found that autosize-input demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.