
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@tanstack/markdown
Advanced tools
A tiny, fast, deterministic Markdown renderer for blogs and documentation.
A tiny, fast, deterministic Markdown renderer for blogs and documentation.
The current browser bundles are 4.6 KB gzip for the parser, 6.4 KB for HTML rendering, and 6.3 KB for the React adapter. The package has no runtime dependencies and does not bundle syntax highlighting.
pnpm add @tanstack/markdown
import { renderHtml } from '@tanstack/markdown/html'
const html = renderHtml('# Fast by default')
import { Markdown } from '@tanstack/markdown/react'
export function Article({ source }: { source: string }) {
return <Markdown>{source}</Markdown>
}
Raw HTML is escaped and executable link protocols are removed by default. allowHtml and highlighter output are explicit trusted-content boundaries.
This is deliberately not a complete CommonMark, GFM, MDX, or content-processing implementation. It implements the syntax used by technical blogs and documentation, then spends its complexity budget on deterministic output, safe defaults, React/HTML parity, malformed-input resilience, and small entry points.
See the docs Markdown profile for the supported contract and deliberate non-goals.
pnpm run verify
To include downstream repositories in the corpus gate:
MARKDOWN_CORPUS_DIRS=../tanstack.com/src/blog:../tanstack.com/docs pnpm run test:corpus
FAQs
A tiny, fast, deterministic Markdown renderer for blogs and documentation.
The npm package @tanstack/markdown receives a total of 133,569 weekly downloads. As such, @tanstack/markdown popularity was classified as popular.
We found that @tanstack/markdown demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.