
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@usestring/mcp
Advanced tools
Official String AI Web Access MCP Server – fetch and search the web via the String AI API from any MCP client
The official Model Context Protocol (MCP) server for String AI's Web Access API. Connect any MCP-compatible client — VS Code, Cursor, Windsurf, Claude Desktop, and more — to String AI's powerful web access capabilities.
| Tool | Description |
|---|---|
web_access_fetch | Fetch any webpage with automatic anti-bot bypass, CAPTCHA handling, and JavaScript rendering |
web_access_search | Search the web with reliable results — bypasses rate limits and bot protection on search engines |
env STRING_AI_API_KEY=your-key npx @usestring/mcp
npm install -g @usestring/mcp
STRING_AI_API_KEY=your-key string-ai-mcp
git clone https://github.com/durable-alpha/string-ai-mcp.git
cd string-ai-mcp
npm install
npm run build
STRING_AI_API_KEY=your-key node build/index.js
| Variable | Required | Description |
|---|---|---|
STRING_AI_API_KEY | Yes | Your String AI API key |
Press Ctrl+Shift+P → Preferences: Open User Settings (JSON) and add:
{
"inputs": [
{
"type": "promptString",
"id": "stringAiKey",
"description": "String AI API Key",
"password": true
}
],
"servers": {
"string-ai": {
"command": "npx",
"args": ["-y", "@usestring/mcp"],
"env": {
"STRING_AI_API_KEY": "${input:stringAiKey}"
}
}
}
}
Or add a .vscode/mcp.json file to share the configuration with your team.
Open Settings → Features → MCP Servers → + Add new global MCP server and paste:
{
"mcpServers": {
"string-ai": {
"command": "npx",
"args": ["-y", "@usestring/mcp"],
"env": {
"STRING_AI_API_KEY": "YOUR_API_KEY"
}
}
}
}
Add to ~/.codeium/windsurf/model_config.json:
{
"mcpServers": {
"string-ai": {
"command": "npx",
"args": ["-y", "@usestring/mcp"],
"env": {
"STRING_AI_API_KEY": "YOUR_API_KEY"
}
}
}
}
Add to your claude_desktop_config.json:
{
"mcpServers": {
"string-ai": {
"command": "npx",
"args": ["-y", "@usestring/mcp"],
"env": {
"STRING_AI_API_KEY": "YOUR_API_KEY"
}
}
}
}
The MCP Inspector lets you test your server interactively in a browser:
npx @modelcontextprotocol/inspector node build/index.js
Then open http://127.0.0.1:6274, connect via stdio, and try calling each
tool from the UI.
┌──────────────────┐ stdio (JSON-RPC) ┌──────────────────┐ HTTPS ┌──────────────────┐
│ VS Code / Cursor │ ◄──────────────────► │ String AI │ ────────► │ String AI │
│ Windsurf / Claude│ │ Web Access MCP │ │ Web Access API │
└──────────────────┘ └──────────────────┘ └──────────────────┘
web_access_fetch
or web_access_search.String AI provides a powerful web access API that handles proxies, anti-bot measures, and JavaScript rendering automatically. Get your API key at usestring.ai.
MIT
FAQs
Official String AI Web Access MCP Server – fetch and search the web via the String AI API from any MCP client
The npm package @usestring/mcp receives a total of 30 weekly downloads. As such, @usestring/mcp popularity was classified as not popular.
We found that @usestring/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.