
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@opentag/telegram
Advanced tools
Telegram message normalization and callback helpers for OpenTag.
Use this package to normalize Telegram bot messages into OpenTagEvent objects
and to encode or parse Telegram callback thread keys.
pnpm add @opentag/telegram
normalizeTelegramMessage: converts a Telegram message into an OpenTagEvent.encodeTelegramThreadKey: encodes bot, chat, and message coordinates for callback routing.parseTelegramThreadKey: decodes a Telegram callback thread key.renderTelegramAcknowledgement: renders the Telegram acknowledgement body.renderTelegramFinalResult: renders the Telegram final result body.createTelegramSendMessagePayload: creates a Telegram Bot API sendMessage payload.import { normalizeTelegramMessage } from "@opentag/telegram";
const event = normalizeTelegramMessage({
botId: "bot_123",
botUsername: "opentag_bot",
chatId: "456",
chatType: "private",
userId: "789",
username: "alice",
text: "investigate this deploy failure",
messageId: 101,
updateId: 202,
binding: {
botId: "bot_123",
chatId: "456",
repoProvider: "github",
owner: "acme",
repo: "demo"
}
});
if (event) {
// Send the event to @opentag/client or your own OpenTag-compatible control plane.
}
Telegram thread key format is public because callback sinks depend on it. Change it only with a migration path.
FAQs
Telegram message normalization and callback helpers for OpenTag.
The npm package @opentag/telegram receives a total of 18 weekly downloads. As such, @opentag/telegram popularity was classified as not popular.
We found that @opentag/telegram demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.