Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
react-beacon
Advanced tools
React Beacon - Onboarding Tooltips using Slack-like Beacons
position
: top, right, bottom or left for tooltip to appear. Default to rightpersistent
: see belowJust place the Beacon
tag inside the target element with the tooltip text as its content:
<div id="some-element-that-I-want-to-explain-to-the-user">
<Beacon>
This is the tooltip text
</Beacon>
</div>
If the persistent
attribute is specified, the component will automatically remember whether the beacon has been
clicked on. If it has already been clicked, it will not be displayed again since generally the user will only want
to see an onboarding tooltip once.
The state of each beacon is stored using a unique ID. If you just set persistent
to true
, a SHA-1 hash will
be calculated from the beacon content and used as the key. This means that all beacons will have a unique key as
long as they also have unique content. You can override this key by specifying some other truthy value for
the persistent
attribute.
IndexedDB is used for storing the beacon state, so if some of your target browsers don't support IndexedDB, you should use a shim.
If desired, the tooltip target can be highlighted by fading the background and enlarging the target when
the beacon is clicked (see screenshot). To activate this functionality, add the class tour-overlay
to
your application root element (i.e. the element that should be faded).
npm install
npm start
react-beacon is released under the MIT license.
FAQs
Onboarding beacons for React
The npm package react-beacon receives a total of 120 weekly downloads. As such, react-beacon popularity was classified as not popular.
We found that react-beacon demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.