
Research
/Security News
77 Firefox Extensions Linked to Crypto Wallet and Credential Theft
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.
@ibanforge/sdk
Advanced tools
Official TypeScript SDK for the IBANforge API — IBAN validation, BIC/SWIFT lookup, Swiss BC-Nummer, SEPA/VoP and compliance risk scoring, with API-key auth, typed errors and x402 support.
Official TypeScript/JavaScript SDK for the IBANforge API — IBAN validation, BIC/SWIFT lookup, Swiss BC-Nummer clearing, SEPA + VoP reachability and compliance risk scoring. Zero runtime dependencies (uses native fetch).
npm install @ibanforge/sdk
import { IBANforge } from '@ibanforge/sdk';
// Free format check — no API key needed
const fmt = await new IBANforge().formatIban('CH9300762011623852957');
console.log(fmt.valid); // true
// Authenticated calls (required for paid endpoints, unless you pay per-call via x402)
const client = new IBANforge({ apiKey: 'ifk_...' });
const r = await client.validateIban('CH9300762011623852957');
console.log(r.valid); // true
console.log(r.bic?.code); // 'UBSWCHZH'
console.log(r.bic?.bank_name); // 'UBS Switzerland AG'
console.log(r.sepa?.member); // true
console.log(r.clearing?.iid); // '00762' (Swiss BC-Nummer, CH/LI only)
const key = await IBANforge.generateApiKey('you@example.com'); // 200 req/month
const client = new IBANforge({ apiKey: key.api_key });
await client.formatIban(iban); // FREE — mod-97 + structure only
await client.validateIban(iban); // full enrichment
await client.validateBatch([...ibans]); // up to 100, $0.002/IBAN
await client.lookupBic('UBSWCHZH80A'); // BIC → bank, country, LEI
await client.lookupChClearing('762'); // Swiss BC-Nummer / IID (only API with this)
await client.checkCompliance(iban); // sanctions + FATF + SEPA + VoP + risk score
await client.usage(); // current month quota for your key
await client.health();
const c = await client.checkCompliance('GB29NWBK60161331926819');
console.log(c.compliance.risk_score); // 0–100
console.log(c.compliance.risk_level); // 'low' | 'medium' | 'elevated' | 'high' | 'critical'
console.log(c.compliance.sanctions.matched_lists); // e.g. ['OFAC']
Sanctions screening is at the bank (BIC8) level — it does not screen the beneficiary name and is not a regulated AML/CFT product.
Every failure throws a typed subclass of IBANforgeError, so an agent can branch on it:
import { IBANforge, PaymentRequiredError, AuthError, RateLimitError } from '@ibanforge/sdk';
try {
await new IBANforge().validateIban('CH9300762011623852957'); // no key → 402
} catch (err) {
if (err instanceof PaymentRequiredError) {
// err.accepts carries the x402 challenge — pay and retry, no dead-end
console.log(err.accepts);
} else if (err instanceof AuthError) {
// bad/expired key
} else if (err instanceof RateLimitError) {
// back off
}
}
new IBANforge({
apiKey: 'ifk_...', // optional
baseUrl: 'https://api.ibanforge.com', // optional override
timeoutMs: 30_000, // optional, default 30s
});
MIT
FAQs
Official TypeScript SDK for the IBANforge API — IBAN validation, BIC/SWIFT lookup, Swiss BC-Nummer, SEPA/VoP and compliance risk scoring, with API-key auth, typed errors and x402 support.
The npm package @ibanforge/sdk receives a total of 14 weekly downloads. As such, @ibanforge/sdk popularity was classified as not popular.
We found that @ibanforge/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.

Security News
NIST disclosed an unreleased AI tool called V-etalon and opened a broad inquiry into NVD modernization after years of automation plans produced no public enrichment system.

Security News
In his AI Council 2026 talk, Feross Aboukhadijeh covers recent package compromises, vulnerability discovery, and a more automated security model.