
Research
/Security News
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.
@fetchproxy/protocol
Advanced tools
Wire-protocol types, runtime validators, and crypto wrappers for the fetchproxy WebSocket protocol.
Internal-ish: most users want @fetchproxy/server instead. @fetchproxy/server re-exports the few protocol types MCP authors typically need (Capability, FetchInit); pull this package in directly only if you're building your own bridge endpoint (alternate server, test harness, custom extension).
See:
docs/PROTOCOL.md — full wire-format reference (frames, handshake, crypto).npm install @fetchproxy/protocol
| Module | Exports | Purpose |
|---|---|---|
frames | PROTOCOL_VERSION, Capability, KNOWN_CAPABILITIES, all …Frame types, FetchInit, ReadCookiesInit, InnerFrame union, StoragePointerDecl, IndexedDbScopeDecl, CaptureHeaderDecl | Static + runtime descriptions of every frame on the wire. |
validate | validateFrame, validateInnerFrame, ProtocolError, HOSTNAME_RE | Defensive JSON validators with no third-party dependencies. Reject prototype-pollution attempts, malformed base64, unknown ops/capabilities, bad hostnames. |
crypto | RawKeyPair, generateX25519, generateEd25519, ecdhX25519, hkdfSha256, ed25519Sign, ed25519Verify, aesGcmSeal, aesGcmOpen, sha256 | Thin async wrappers around WebCrypto subtle. Used by both server and extension. |
mcp-id | generateMcpId, parseMcpId, isValidMcpId, McpIdParts | Per-process <serverName>:<version>:<rand> ids. |
pair-code | derivePairCode, derivePairCodeFromIds | Deterministic 6-digit SAS code from X25519 pubkey(s) (SHA256[0..3] mod 1_000_000, formatted XXX-XXX). |
seal | sealInnerFrame, openEncryptedFrame | AES-256-GCM encrypt/decrypt of inner JSON payloads keyed by sessionKey. |
encoding | toB64, fromB64, toHex, concatBytes | Shared base64/hex helpers. |
json-pointer | evalJsonPointer, isValidJsonPointer, matchesDeclaredKey, undeclaredKeys | JSON-pointer evaluation + glob matching for storage-pointer extraction. |
All exports are part of the published surface and follow semver:
0.2.0 was a wire-incompatible jump from 0.1.x (singular domain: string → domains: string[]; added capabilities; added op discriminator on inner request/response).
MIT.
FAQs
WebSocket frame types + runtime validators for fetchproxy.
We found that @fetchproxy/protocol demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.