
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@buoy-design/cli
Advanced tools
Catch design drift before it ships. Buoy scans your codebase to find where AI-generated code diverges from your design system.
npx ahoybuoy show all
This scans your project without requiring configuration.
#3b82f6 instead of design tokenspadding: 17px instead of spacing variables| Command | Purpose |
|---|---|
buoy show all | Scan for components, tokens, and drift |
buoy drift check | Pre-commit drift validation |
buoy drift fix | Preview or apply drift fixes |
buoy rescue | Measure, repair, guard, and prove improvement |
buoy dock | Configure project (agents, hooks, etc.) |
buoy ahoy | Cloud features (login, GitHub bot, billing) |
The buoy drift fix command suggests and applies fixes for design drift:
buoy drift fix # Preview fixable issues
buoy drift fix --dry-run # Show detailed diffs
buoy drift fix --apply # Apply high-confidence fixes
buoy drift fix --confidence=high # Require high-confidence matches
For an existing codebase, Rescue turns the commands into one reviewable journey:
buoy rescue plan
# Review .buoy/rescue/runs/<run-id>/report.html
buoy rescue apply --run <run-id> --approve
buoy rescue guard --run <run-id> --reason "Reviewed legacy baseline"
buoy rescue report --run <run-id>
Apply requires a clean Git worktree and creates a new buoy/<run-id> branch.
Buoy never commits, pushes, merges, or uploads source code. Ambiguous changes stay
review-required, and buoy rescue rollback restores local backups.
| Level | Score | Description |
|---|---|---|
| exact | 100% | Value exactly matches a design token |
| high | 95-99% | Very close match, safe to auto-apply |
| medium | 70-94% | Close match, review recommended |
| low | <70% | Ambiguous, manual review required |
Buoy works great with AI coding tools:
# Set up AI agents with design system context
buoy dock agents
# Generate CLAUDE.md context
buoy dock context
Buoy auto-detects your framework (React, Vue, Svelte, Angular, Astro) and scans standard paths. No configuration required to get started.
Off by default. After your first drift result in an interactive terminal, Buoy asks once whether it may send anonymous usage pings. Say no and it never asks again.
If you opt in, it sends event names (cli_first_run, cli_drift_found, cli_check_clean, cli_hint_shown, cli_login_started) with counts, the CLI version, and your OS. Never file paths, repository names, code, or account details. A random id in ~/.buoy/config.json groups pings from one install and is not tied to you.
buoy ahoy telemetry # show the setting and the exact payload
buoy ahoy telemetry off # or on
BUOY_TELEMETRY=0, DO_NOT_TRACK=1, or CI in the environment disables it regardless of the setting. JSON and quiet output never send.
FAQs
Catch design drift before it ships
The npm package @buoy-design/cli receives a total of 216 weekly downloads. As such, @buoy-design/cli popularity was classified as not popular.
We found that @buoy-design/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.