
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
A tiny, dependency-free, color input field helper that utilizes the native color picker.
Visit https://colortap.js.org
Download the latest version of colortap and then place the following HTML in your page's head element:
<script type="text/javascript" src="dist/colortap.min.js"></script>
<link rel="stylesheet" href="dist/colortap.min.css" />
Place the following HTML in your page's head element (check to make sure the version in the URLs are the version you want):
<script type="text/javascript" src="https://cdn.jsdelivr.net/gh/fivefifteen/colortap@0.3/dist/colortap.min.js"></script>
<link rel="stylesheet" href="https://cdn.jsdelivr.net/gh/fivefifteen/colortap@0.3/dist/colortap.min.css" />
npm install colortap --save
// ES6
import colortap from 'colortap'
// CommonJS
const colortap = require('colortap')
fetcher install fivefifteen/colortap --save
bower install fivefifteen/colortap --save
<div class="colortap">
<input type="color" id="main-color" value="#5185b3">
<button type="button" class="colortap-open colortap-value" data-colortap-style-prop="background-color"></button>
</div>
colortap
FunctionInitiates colortap on any element that has the colortap
class. This should be a container around your color input.
window.addEventListener('load', function () {
colortap()
})
The colortap-input
class - Any input element with this class will have it's value set to the selected color any time the color is changed. The color will also be set to any value that is entered into this input field.
The colortap-open
class - Any element with this class will open the color picker when clicked.
The colortap-value
class - Any element with this class will have it's text content set to the color when the color is changed. If this element is an input, it's value will be updated instead of text content.
The data-colortap-style-prop
attribute - Set this attribute to a style property (like background
or color
) on an element to have it's style updated when the color is changed. Multiple style properties can be defined by separating them with a comma (ie. background,color
).
The containing colortap element (the element with the colortap
class) will have the following methods attached to it available for use:
var color = document.querySelector('.color')
color.open() // Opens the color picker
color.set('#00ff00') // Sets the color
var currentColor = color.get() // Gets the current color
// The `change` event bubbles up to the containing element so you can detect changes like so:
color.addEventListener('change', function () {
document.body.style.setProperty('--color', event.target.value)
})
FileBokz - A tiny, dependency-free, highly customizable and configurable, easy to use file input with some pretty sweet features.
GrowField - A tiny, dependency-free JavaScript module for making textarea elements grow with their content.
HashJump - A tiny, dependency-free JavaScript module for handling anchor links and scrolling elements into view.
Kloner - A tiny, dependency-free JavaScript module for cloning/repeating elements.
MIT. See the license file for more info.
FAQs
A tiny, dependency-free, color input field helper that utilizes the native color picker.
The npm package colortap receives a total of 1 weekly downloads. As such, colortap popularity was classified as not popular.
We found that colortap demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.