
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
Lexu from the command line: generate images, video and music with your lexu.io credits
Create images, video and music with your lexu.io credits from code, the terminal, or an AI assistant.
| Package | What it is |
|---|---|
@lexu/sdk | TypeScript client for the Lexu API v1 |
@lexu/cli | The lexu command |
@lexu/mcp | MCP server for Claude Desktop, Claude Code, Cursor and other MCP clients |
Every generation is charged to your Lexu balance, at the same price as on the website. Each API key also has a monthly credit cap (500 by default, 200 for MCP keys), so a leaked key can only spend that much. Manage keys at https://www.lexu.io/dashboard/settings/api-keys.
npx @lexu/cli login # approve in the browser; no password in the terminal
npx @lexu/cli balance
npx @lexu/cli models --type video
npx @lexu/cli estimate kling-3 --duration 10
npx @lexu/cli generate gpt-image-2.5 "a red perfume bottle on white marble" --aspect-ratio 1:1 --download
npx @lexu/cli generate seedance-2-mini "waves at sunset, slow motion" --duration 5 --yes --json
npx @lexu/cli jobs
npx @lexu/cli job <id> --wait --download --out ./renders
npx @lexu/cli logout # also revokes the key on the server
Before charging, generate shows the price and asks. In scripts, pass --yes. --json prints machine-readable output. In CI, set LEXU_API_KEY instead of logging in.
Model options are passed as flags: --aspect-ratio 9:16 becomes aspect_ratio. lexu models lists each model's options.
Log in once (creates a key with a 200-credit monthly cap):
npx @lexu/mcp login
Claude Desktop (claude_desktop_config.json) or any MCP client:
{
"mcpServers": {
"lexu": { "command": "npx", "args": ["-y", "@lexu/mcp"] }
}
}
Claude Code:
claude mcp add lexu -- npx -y @lexu/mcp
Instead of logging in, you can put a key in the client config: "env": { "LEXU_API_KEY": "lexu_live_..." }.
Tools: get_account, get_balance, list_models, estimate_cost, generate_image, generate_video, generate_music, get_generation, list_generations, plus the product_ad prompt.
Every generate_* tool requires max_credits. The server estimates the request first and refuses it if it costs more, so text injected into a web page or file cannot make the assistant overspend.
import { Lexu } from "@lexu/sdk";
const lexu = new Lexu({ apiKey: process.env.LEXU_API_KEY! });
const { credits } = await lexu.estimate({ model: "veo-3.1-lite", prompt: "…", duration: 8 });
const started = await lexu.generate({ model: "veo-3.1-lite", prompt: "…", duration: 8 });
const done = await lexu.waitForGeneration(started.id);
console.log(done.status, done.output_url);
generate() sends an Idempotency-Key and retries network failures with the same key, so a retry never charges twice. Failed generations are refunded automatically; refunded is then true.
Base URL: https://www.lexu.io/api. Send Authorization: Bearer lexu_live_….
| Method | Path | |
|---|---|---|
| GET | /v1/me | Account and plan |
| GET | /v1/balance | Credits and this key's monthly cap |
| GET | /v1/models | Models, inputs, prices (no key needed) |
| POST | /v1/estimate | Price of a request, no charge |
| POST | /v1/generations | Start; requires Idempotency-Key |
| GET | /v1/generations | History (?limit, ?before) |
| GET | /v1/generations/{id} | Status and a fresh download link |
| GET | /v1/ledger | Balance changes |
| DELETE | /v1/keys/current | Revoke the key used |
Answers are { "data": … } or { "error": { "code", "message" } }.
npm install
npm run build
npm test
The server side lives in the lexu-platform repository: supabase/functions/api-v1 and migration 00053_public_api_keys.sql.
FAQs
Lexu from the command line: generate images, video and music with your lexu.io credits
We found that @lexu/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.