
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
@agonx402/types
Advanced tools
Shared TypeScript type definitions for the Agon payment protocol.
Used internally by @agonx402/client and @agonx402/platform. You typically don't need to install this directly — it's included as a dependency of both SDKs.
npm install @agonx402/types
Account, AccountBalance, AutoRefillSettings, deposit/withdrawal typesAuthorizeRequest/Response, ConsumeRequest/Response, ReleaseRequest/ResponseSpendingControls, SpendingOverride, SpendingLimitExceededDetailsApiPlatform, RegisterPlatformRequest/ResponseProxyRequest/Response for x402 compatibility modeSettlement, SettlementBatch for batch on-chain payoutsAgonError class with typed error codes and helper methodsAgonPlatformConfig, OverrideSigner, pricing utilitiesAGON_HEADERS, USDC (mints, decimals), parsePrice()1 USDC = 1_000_000 unitssnake_case, SDK-facing types use camelCaseAGON is an early-stage, devnet payment infrastructure project. It functions as a custodial service: after deposit, funds are swept to and held in project-controlled wallets.
While the core payment flows are operational, the platform is still under active development and has not yet undergone a formal security audit or obtained insurance coverage. The project is also in the process of completing VASP registration in Georgia.
As with any early-stage financial technology, there are material risks including (but not limited to) technical failures, operational errors, or unforeseen events that could result in loss of funds.
We strongly recommend testing with very small amounts only and monitoring your activity closely.
We are committed to transparency and continuous improvement — live Proof of Reserves, public multisig wallets, and regular updates are available on the site.
MIT
FAQs
Shared type definitions for the Agon payment SDK
We found that @agonx402/types demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.