
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@paneui/core
Advanced tools
Pane relay client: typed HTTP + WebSocket operations against a Pane relay. Framework-free.
Typed client for the Pane relay HTTP + WebSocket API. Framework-free: no argv, no MCP, no server dependencies — just the relay protocol expressed as typed operations.
@paneui/core targets the Node.js runtime (>= 20, as declared in
package.json's engines). It is framework-free, not runtime-free.
The WebSocket transport (openStream) uses the ws
package rather than the global WebSocket. ws exposes a Node-style event API
(socket.on("message", ...), custom upgrade headers such as Authorization)
that the browser WebSocket does not, and the relay protocol relies on it.
Because of this, @paneui/core is not intended to run in a browser or other
non-Node runtime as-is.
The HTTP pane (PaneClient, registerAgent) uses the standard fetch API
and is runtime-agnostic; only openStream carries the Node constraint.
If you need a browser client, treat that as separate future work — it would
need a ws-vs-global-WebSocket abstraction rather than the unconditional
import { WebSocket } from "ws" used today.
PaneClient / PaneApiError — typed HTTP operations against a relay.openStream — WebSocket stream (replay-on-connect, then live). Node only.registerAgent — agent registration helper.artifactSchema, callbackSchema, createPaneSchema — Zod schemas.FAQs
Pane relay client: typed HTTP + WebSocket operations against a Pane relay. Framework-free.
The npm package @paneui/core receives a total of 12 weekly downloads. As such, @paneui/core popularity was classified as not popular.
We found that @paneui/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.