Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
bad-behavior
Advanced tools
Super-tiny observable. That's literally all it is.
Sometimes RxJs feels like overkill. It is a wonderful library, but sometimes you need a little bit of reactivity, not a whole system of reactivity. This library is an approximation of the BehaviorSubject
, one of the most useful Observables out there. In truth, bad-behavior is nothing more than a fancy multi-cast event emitter.
// if using NPM, import it, otherwise it should already be on window
import BadBehavior from 'bad-behavior'
// create a bad behavior
let obs = BadBehavior()
// subscribe to listen for new values
let sub1 = obs.subscribe(s => { console.log(s) })
let sub2 = obs.subscribe(s => { console.error(s) })
// call next to publish a new value
obs.next(10)
// unsubscribe to stop listening
sub.unsubscribe()
I kept reusing this piece of code to build animation libraries, especially when building micro-libraries. I figured, why not share this little piece of code with everyone? Plus I got sick of copying and pasting it...
npm i -S bad-behavior
OR
<script src="https://unpkg.com/bad-behavior/dist/cdn/bad-behavior.min.js"></script>
bad-behavior
is licensed under the MIT license.
FAQs
Super-tiny observable. That's literally all it is.
The npm package bad-behavior receives a total of 2,377 weekly downloads. As such, bad-behavior popularity was classified as popular.
We found that bad-behavior demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.