
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@stlw/warden-hook-server
Advanced tools
HTTP hook server for Claude Code, Codex CLI, and Copilot SDK integration
Local HTTP hooks that apply Warden policy to Claude Code, Codex CLI, and Copilot SDK tool calls. The server handles session lifecycle, prompt submission, pre-tool decisions, post-tool output tagging, and an auditable ledger.
npm install @stlw/warden-hook-server @stlw/warden
startHookServer reads your PolicyConfig, defaults to port 7429, and returns the server handle:
import { startHookServer } from "@stlw/warden-hook-server";
import type { PolicyConfig } from "@stlw/warden";
const config: PolicyConfig = {
version: "2",
meta: { environment: "development", sessionApprovalRequired: false },
policies: [
{
id: "allow-reads",
description: "Allow read tools during development",
match: { tools: ["read_file", "list_directory"], environment: ["development"] },
action: "ALLOW",
},
],
};
startHookServer({ config, dbPath: ".warden/ledger.db", port: 7429 });
Set WARDEN_AUTH_TOKEN (or pass authToken) to require X-Warden-Auth on hook requests. /health remains available for readiness checks:
curl http://localhost:7429/health
For Claude Code, point its HTTP hooks at http://localhost:7429/hooks/... and include the shared-secret header. The CLI configures the same server with warden start; use that for the quickest setup.
See the public manual for the complete Claude Code settings example and OpenCode integration.
FAQs
HTTP hook server implementing Warden's local decision contract
The npm package @stlw/warden-hook-server receives a total of 391 weekly downloads. As such, @stlw/warden-hook-server popularity was classified as not popular.
We found that @stlw/warden-hook-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.