
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
float-tooltip
Advanced tools
A floating tooltip JS component.
import Tooltip from 'float-tooltip';
or using a script tag
<script src="//cdn.jsdelivr.net/npm/float-tooltip"></script>
then
const myTooltip = new Tooltip(<triggerDOMElement>)
.content('<div>Hello World!</div>');
new Tooltip(<containerDomElement>, { configOptions })
Config options | Description | Default |
---|---|---|
style: object | A custom style object apply to the tooltip and override the default style. | - |
Method | Description | Default |
---|---|---|
content([string | HTMLElement]) | Specify the content of the tooltip. Supports plain text, HTML string content, an HTML element or React JSX. If a falsy value is supplied the tooltip will automatically hide. |
offsetX([number]) | The amount of pixels to offset the tooltip horizontally from its center position relative to the pointer. If a null value is specified (default) the offset will be automatically calculated and gradually shifted so it remains horizontally inside the parent element. | - |
offsetY([number]) | The amount of pixels to offset the tooltip vertically relative to the pointer. A negative value will shift the tooltip to be above the pointer. If a null value is specified (default) the tooltip will be flipped above when the pointer is near the bottom, so it remains vertically inside the parent element. | - |
If this project has helped you and you'd like to contribute back, you can always buy me a ☕!
FAQs
Floating tooltip component
The npm package float-tooltip receives a total of 108,529 weekly downloads. As such, float-tooltip popularity was classified as popular.
We found that float-tooltip demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.