
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
@warmio/mcp
Advanced tools
@warmio/mcp is Warm's local stdio MCP server. Run the interactive installer to validate and store one full-access WARM_API_KEY, then configure detected supported clients:
npx -y @warmio/mcp@latest install
Each client starts the server with:
npx -y @warmio/mcp@latest mcp
The server exposes financial-context read tools plus the automation operation catalog. The installer
stores the local credential with owner-only file permissions. Importing @warmio/mcp exposes the
library API without starting the CLI.
For Cursor users, install the official Warm plugin directly from the Cursor Marketplace for one-click setup. The plugin is also available at .cursor-plugin/ in this package.
FAQs
Warm local stdio MCP server
The npm package @warmio/mcp receives a total of 547 weekly downloads. As such, @warmio/mcp popularity was classified as not popular.
We found that @warmio/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.