Research
Security News
Threat Actor Exposes Playbook for Exploiting npm to Build Blockchain-Powered Botnets
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
keyboard selectable toolbar for selecting an active tool
when users hit 0-9 on their keyboard or click an item on the toolbar toolbar
will emit a javascript event that will tell you which item in the toolbar has been selected
step 1:
npm install toolbar
step 2:
include some html in your page that looks like this:
<nav class="bar-tab">
<ul class="tab-inner">
<li class="tab-item active">
<a href="">
<img class="tab-icon" src="icons/first-tool.png">
<div class="tab-label">First Tool</div>
</a>
</li>
<li class="tab-item">
<a href="">
<img class="tab-icon" src="icons/second-tool.png">
<div class="tab-label">Second Tool</div>
</a>
</li>
</ul>
</nav>
step 3:
var toolbar = require('toolbar')
var bartab = toolbar('.bar-tab')
use browserify to package toolbar for use in your client side app!
step 4:
bartab.on('select', function(item) {
// item is the .tab-label innerText
})
to convert svgs from the noun project into cute little transparent pngs:
mogrify -fill "#ffffff" -opaque "#000000" -background none -format png *.svg
BSD
FAQs
client side module for creating toolbars
The npm package toolbar receives a total of 131 weekly downloads. As such, toolbar popularity was classified as not popular.
We found that toolbar demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
Security News
NVD’s backlog surpasses 20,000 CVEs as analysis slows and NIST announces new system updates to address ongoing delays.
Security News
Research
A malicious npm package disguised as a WhatsApp client is exploiting authentication flows with a remote kill switch to exfiltrate data and destroy files.