
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@layers/amba-mcp
Advanced tools
MCP server tools for amba — agentic developer onboarding, project provisioning, and SDK introspection over the Model Context Protocol.
Amba is the agent-native backend-as-a-service for mobile and web apps. This package is the Model Context Protocol (MCP) tool registry that lets an AI agent drive the Amba admin API directly.
It exposes ~178 tools across ~17 groups (projects, push, segments, config, content, users, achievements, challenges, economy, leaderboards, platform, social, xp, events, auth, …) and is the same registry that powers the hosted MCP server at mcp.amba.dev.
npm install @layers/amba-mcp@1.0.1
This package is a tool registry, not a transport. You mount it into your own MCP server:
import { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js';
import { registerAllTools, createApiClient } from '@layers/amba-mcp';
const server = new McpServer({ name: 'amba-mcp', version: '1.0.0' });
const apiClient = createApiClient({
baseUrl: 'https://api.amba.dev/v1/admin',
token: process.env.AMBA_DEVELOPER_TOKEN,
});
registerAllTools(server, apiClient);
// Then mount `server` behind any MCP transport (stdio, Streamable HTTP, SSE).
Every tool except the public auth tools (amba_developer_signup, amba_developer_login, amba_developer_refresh) requires a developer Bearer token.
amba_developer_signup with no Authorization header — the response includes a long-lived Personal Access Token (pat) and a freshly provisioned project. While new accounts are invite-only, include invite_code; a missing or rejected code answers 403 INVITE_REQUIRED / INVITE_INVALID (and SIGNUPS_CLOSED when no accounts are being created), with error.details.request_access_url pointing at the request-access page.pat as the inbound Bearer on every subsequent MCP call.amba_get_provisioning_status until the project flips to status: "active" before issuing client traffic.Omit token on createApiClient to fall back to the CLI credential file at ~/.amba/credentials.json.
Tool reference: https://docs.amba.dev/mcp.
Apache-2.0
FAQs
MCP server tools for amba — agentic developer onboarding, project provisioning, and SDK introspection over the Model Context Protocol.
The npm package @layers/amba-mcp receives a total of 397 weekly downloads. As such, @layers/amba-mcp popularity was classified as not popular.
We found that @layers/amba-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.