
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@pymodel/pythinker-code
Advanced tools
The Starting Point for Next-Gen Agents
Pythinker Code CLI is an AI coding agent that runs in your terminal. It can read and edit code, run shell commands, search files, fetch web pages, and choose the next step based on the feedback it receives. It works out of the box with PyModel's Pythinker models and can also be configured to use other compatible providers.
Install with npm. Node.js 22.19.0 or later is required:
npm install -g @pymodel/pythinker-code
On Windows, install Git for Windows before first launch because Pythinker Code CLI uses the bundled Git Bash as its shell environment. If Git Bash is installed in a custom location, set
PYTHINKER_SHELL_PATHto the absolute path ofbash.exe.
Then run it with a new Terminal session:
pythinker --version
For upgrade and uninstall instructions, see the Getting Started guide.
Open a project and start the interactive UI:
cd your-project
pythinker
On first launch, run /login inside Pythinker Code CLI and choose either Pythinker Code OAuth or a Kimi Platform API key. After login, try a first task:
Take a look at this project and explain the main directories.
/mcp-config — no hand-editing JSON.coder, explore, and plan subagents in isolated context windows; the main conversation stays clean.MIT
FAQs
The Starting Point for Next-Gen Agents
The npm package @pymodel/pythinker-code receives a total of 763 weekly downloads. As such, @pymodel/pythinker-code popularity was classified as not popular.
We found that @pymodel/pythinker-code demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.