
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@chain305/x-security
Advanced tools
x-security CLI — generate/validate/test/report/diff/init against multiple gateway targets
Compile, validate, test, and report on x-security policies in OpenAPI specs — deterministic, no LLM calls, no API keys.
npx @chain305/x-security --help
| Command | What it does |
|---|---|
x-security generate <spec> --target <t> | Compile an annotated OpenAPI spec into gateway config (kong, coraza, bunkerweb, openappsec, firewall, envoy) |
x-security validate <spec> --target kong --gateway <url|file> | Detect drift between the spec and a running/exported gateway config |
x-security test <spec> --target <t> | Closed-loop test: generate config, spin up Docker, send traffic, assert |
x-security verify <spec> --target <t> --gateway <addr> | Read-only post-deploy check that the gateway loaded the emitted artifacts |
x-security report <spec> | OWASP API Top 10 coverage and annotation reports |
x-security diff <old> <new> --target <t> | Diff the generated config for two spec versions |
x-security init <spec> | Add empty x-security blocks to operations missing them |
x-security migrate <spec> --from 0.4 --to 0.5 | Rewrite a spec between schema versions |
Run x-security <command> --help for full flags.
x-security test)Apache-2.0
FAQs
x-security CLI — generate/validate/test/report/diff/init against multiple gateway targets
The npm package @chain305/x-security receives a total of 9 weekly downloads. As such, @chain305/x-security popularity was classified as not popular.
We found that @chain305/x-security demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.