
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@stlw/warden-hook-server
Advanced tools
HTTP hook server for Claude Code, Codex CLI, and Copilot SDK integration
@stlw/warden-hook-server exposes local HTTP policy hooks for Claude Code, Codex CLI, and Copilot SDK integrations.
npm install @stlw/warden-hook-server @stlw/warden
import { createHookServer, startHookServer } from "@stlw/warden-hook-server";
const app = createHookServer({ config });
await startHookServer(app, 7429);
See the Warden manual for client configuration.
FAQs
HTTP hook server implementing Warden's local decision contract
The npm package @stlw/warden-hook-server receives a total of 272 weekly downloads. As such, @stlw/warden-hook-server popularity was classified as not popular.
We found that @stlw/warden-hook-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.