
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
npm install --save lqip
Generating Base64 from an image:
const lqip = require('lqip');
const file = `./dest/to/file/zouhir-riding-a-bike.jpg`;
lqip.base64(file).then(res => {
console.log(res); // "data:image/jpeg;base64,/9j/2wBDAAYEBQYFBAYGBQYHBwYIChAKCgkJChQODwwQFxQYGBcUFhY.....
});
Generating colour palette from an image:
const lqip = require('lqip');
const file = `./dest/to/file/zouhir-riding-a-bike.jpg`;
lqip.palette(file).then(res => {
// the response will be sorted from most dominant colour to least
console.log(res); // [ '#628792', '#bed4d5', '#5d4340', '#ba454d', '#c5dce4', '#551f24' ]
});
lqip.base64(filePath: string)
This method accepts an image file path, the file has to be one of those formats ['jpeg', 'jpg', 'png'] and returns a Base64
image string with a valid format and ready to be used in web applications such as in tags source or in CSS properties URLs.
lqip.palette(filePath: string)
This method accepts an image file path, and returns an colour palette as an array of HEX colour values. The array that is returned is sorted from the most to the least dominant colour.
Related projects to this would be lqip-loader for webpack as well as lqip-cli.
Thanks to contributors and Colin van Eenige for his reviews and early testing.
MIT - Zouhir Chahoud
FAQs
Low Quality Image Placeholders (LQIP) Module for Node
The npm package lqip receives a total of 2,232 weekly downloads. As such, lqip popularity was classified as popular.
We found that lqip demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.