
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@lexical/internal
Advanced tools
Internal Lexical utilities shared across packages. Do not import directly; no semver guarantees apply to its API.
@lexical/internal[!WARNING] This package contains internal utilities shared across the Lexical packages:
invariant/devInvariant,createError, dev/prod error- and warning-message formatting,warnOnlyOnce, and theLEXICAL_VERSIONconstant. These are bound to the build's transforms and are inlined into every other package rather than shipped as a runtime dependency, so it is published only so the modules resolve through normal package resolution — including thesourceexport condition used when developing against a linked checkout.It is not a public API. Import from
lexicaland the@lexical/*feature packages instead. Nothing here follows semver and any export may change or disappear without notice.
createError('Message with %s', value) constructs an Error without throwing
it, for example to pass to an editor's onWarn handler. It shares invariant's
literal-message and %s argument convention, including production error-code
extraction, and can be used inside expressions.
The transform recognizes the default import from
@lexical/internal/createError (or its .js alias), including renamed imports.
Unrelated or shadowed functions with the same name are left alone. Generated
calls use separate createDevError and createProdError runtime helpers so
bundled output can pass through the transform again.
Warnings routed through createError, including the update-cascade warning,
use the minified error message in production builds with extracted error codes.
Arguments such as the editor namespace are encoded as v parameters in the
decoder URL instead of appearing directly in the message text. Telemetry that
matches the full development warning text must account for that production form.
FAQs
Internal Lexical utilities shared across packages. Do not import directly; no semver guarantees apply to its API.
The npm package @lexical/internal receives a total of 1,630,140 weekly downloads. As such, @lexical/internal popularity was classified as popular.
We found that @lexical/internal demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.