
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
Refs in React, but easy. A dependency-less, replacement for string refs in react.js. Motivated by all sorts of copy paste refName in our react classes. You need the refs to do beautiful animations with GSAP, so might as well make it painless.
yarn add rrf
Create a ref by calling ref with a reference to this, and the name you want the ref to use. If the name ends with an 's' a plural reference will be created. A plural reference allows you to easily create an array of refs to similar objects.
ref(this, 'name')
import React, { Component } from 'react'
import ref from 'rrf'
export default class TheBest extends Component {
componentDidMount() {
console.log(this.refs.div) // div
}
render() {
return <div ref={ref(this, 'div')} />
}
}
import React, { Component } from 'react'
import ref from 'rrf'
export default class TheBest extends Component {
componentDidMount() {
console.log(this.refs.divs) // [div, div, div, div]
}
render() {
return (
<div>
<div ref={ref(this, 'divs')} />
<div ref={ref(this, 'divs')} />
<div ref={ref(this, 'divs')} />
<div ref={ref(this, 'divs')} />
</div>
)
}
}
import React, { Component } from 'react'
import ref from 'rrf'
export default class TheBest extends Component {
componentDidMount() {
console.log(this.refs.div) // div
}
render() {
return (
<div>
<Child reference={ref(this, 'div')} />
</div>
)
}
}
function Child({ reference }) {
return <div ref={reference} />
}
FAQs
React Refs made easy.
We found that rrf demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.