
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@lucianfialho/gmp-cli
Advanced tools
Google Marketing Platform CLI — GA4, Search Console, Ads, GTM. Built for AI agents and power users.
A CLI for the Google Marketing Platform — GA4, Search Console, Google Ads, Tag Manager, and BigQuery.
Built for AI agents (Gemini CLI, Claude Code) and power users. Pipe JSON output to jq, feed it to your agent, or use it in shell scripts.
npm install -g @lucianfialho/gmp-cli
Or from source:
git clone https://github.com/lucianfialho/gmp-cli.git
cd gmp-cli
npm install && npm run build && npm link
gmp gsc)gmp ads)http://localhost:3847/callback to Authorized redirect URIs# Set your OAuth credentials
gmp auth set-credentials --client-id YOUR_ID --client-secret YOUR_SECRET
# Login (opens your browser)
gmp auth login
# Check status
gmp auth status
# Logout
gmp auth logout
Tokens are stored in ~/.config/gmp-cli/tokens.json and auto-refresh.
Google Ads API requires a developer token in addition to OAuth:
gmp auth set-developer-token YOUR_DEVELOPER_TOKEN
If you use a Manager Account (MCC), set your login customer ID:
gmp auth set-login-customer-id 1234567890
gmp ga accounts
gmp ga properties -a 123456789
# Sessions and bounce rate by page, last 30 days
gmp ga report -p 123456789 -m sessions,bounceRate -d pagePath -r 30d
# With filter
gmp ga report -p 123456789 -m sessions -d pagePath --filter "pagePath==/product"
# Custom date range
gmp ga report -p 123456789 -m sessions -r 2024-01-01..2024-01-31
# Output as table or CSV
gmp ga report -p 123456789 -m sessions -d pagePath -f table
gmp ga report -p 123456789 -m sessions -d pagePath -f csv > report.csv
gmp ga realtime -p 123456789 -m activeUsers
gmp ga realtime -p 123456789 -m activeUsers -d country -f table
gmp ga metadata -p 123456789
gmp ga metadata -p 123456789 --type metrics -f table
gmp ga check -p 123456789 -m sessions,bounceRate -d pagePath
gmp gsc sites
# Top queries, last 28 days
gmp gsc report -s "https://example.com/" -d query -l 10 -f table
# Pages with most clicks
gmp gsc report -s "https://example.com/" -d page -l 10 -f table
# Queries by date
gmp gsc report -s "https://example.com/" -d query,date -r 7d -f table
# Filter by query
gmp gsc report -s "https://example.com/" -d query --query "your keyword" -f table
# Filter by page
gmp gsc report -s "https://example.com/" -d query --page "/blog" -f table
# Custom date range
gmp gsc report -s "https://example.com/" -d query -r 2024-01-01..2024-01-31
gmp gsc inspect -u "https://example.com/page" -s "https://example.com/"
gmp gsc sitemaps -s "https://example.com/"
# Simple list (no MCC needed)
gmp ads accounts
# Detailed list via MCC
gmp ads accounts -c 1234567890 -f table
gmp ads campaigns -c 1234567890 -r LAST_30_DAYS -f table
gmp ads campaigns -c 1234567890 --status ENABLED -f table
gmp ads adgroups -c 1234567890 -f table
gmp ads adgroups -c 1234567890 --campaign "Brand" -f table
gmp ads keywords -c 1234567890 -f table
gmp ads keywords -c 1234567890 --campaign "Brand" -l 20 -f table
gmp ads search-terms -c 1234567890 -f table
gmp ads query -c 1234567890 -q "SELECT campaign.name, metrics.clicks FROM campaign WHERE segments.date DURING LAST_7_DAYS"
gmp gtm accounts
gmp gtm containers -a ACCOUNT_ID
# Uses default workspace automatically
gmp gtm tags -p accounts/X/containers/Y -f table
gmp gtm triggers -p accounts/X/containers/Y -f table
gmp gtm variables -p accounts/X/containers/Y -f table
# Specific workspace
gmp gtm tags -p accounts/X/containers/Y -w 3 -f table
JSON output includes the full API payload — parameter[], filter[], fingerprint, path, and blockingTriggerId[]. Use -f json for audits and automation:
# Find all variable references used inside tag parameters (unused variable audit)
gmp gtm tags -p accounts/X/containers/Y -f json \
| jq -r '[.[].parameter[]? | .. | strings | scan("\\{\\{([^}]+)\\}\\}")][]' \
| sort -u
gmp gtm versions -p accounts/X/containers/Y -f table
Query GA4, Google Ads, and GSC data exported to BigQuery using pre-built templates or custom SQL.
Note: Requires re-running
gmp auth loginto grant thebigquery.readonlyscope.
gmp bq templates -f table
gmp bq templates --service ga4
gmp bq templates --service ads
gmp bq templates --service gsc
# GA4: Flatten nested event_params
gmp bq query -t ga4-events-flat --project my-project --dataset analytics_123456789 -r 30d
# GA4: Funnel analysis
gmp bq query -t ga4-funnel --project my-project --dataset analytics_123456789 -r 90d -f table
# GA4: Multi-touch attribution
gmp bq query -t ga4-attribution --project my-project --dataset analytics_123456789 -r 2024-01-01..2024-03-31
# Ads: Wasted spend (search terms with zero conversions)
gmp bq query -t ads-wasted-spend --project my-project --dataset my_ads_data -r 30d -f table
# GSC: Top pages by clicks
gmp bq query -t gsc-top-pages --project my-project --dataset searchconsole -r 90d -f table
# GSC: Keyword cannibalization detection
gmp bq query -t gsc-cannibalization --project my-project --dataset searchconsole -r 90d -f table
# List tables
gmp bq explore --project my-project --dataset analytics_123456789
# Show schema for a specific table
gmp bq explore --project my-project --dataset analytics_123456789 --table events_20240101
gmp bq custom --project my-project -q "SELECT event_date, COUNT(*) as events FROM \`my-project.analytics_123456789.events_20240101\` GROUP BY event_date"
| Template | Service | Description |
|---|---|---|
ga4-events-flat | GA4 | Flatten nested event_params into columns |
ga4-funnel | GA4 | Funnel analysis from event sequences |
ga4-attribution | GA4 | Multi-touch attribution (source/medium) |
ga4-user-journey | GA4 | Session-level page paths |
ga4-ecommerce | GA4 | Purchase/revenue with product detail |
ga4-retention | GA4 | Weekly cohort retention |
ads-wasted-spend | Ads | Search terms with spend, zero conversions |
ads-quality-trend | Ads | Keyword quality score over time |
ads-cross-campaign | Ads | Cross-campaign performance comparison |
gsc-top-pages | GSC | Top pages by clicks with CTR/position |
gsc-query-clusters | GSC | Top queries by volume |
gsc-cannibalization | GSC | Queries with multiple competing pages |
All commands support -f / --format:
| Format | Description |
|---|---|
json | JSON (default) — best for piping to jq or AI agents |
table | Human-readable table |
csv | CSV — pipe to file or other tools |
jq or AI agents), table, CSVSee ROADMAP.md for what's next.
Apache 2.0
FAQs
Google Marketing Platform CLI — GA4, Search Console, Ads, GTM. Built for AI agents and power users.
We found that @lucianfialho/gmp-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.