
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@workflow/core
Advanced tools
Core runtime package for Workflow SDK.
Steps wait for released stream writers to drain before recording completion. Streams that finish draining after the inline wait budget expires do not force an extra queued continuation unless other background operations remain pending.
Hook registration acknowledgements and token conflicts participate in replay
delivery ordering alongside step results, hook payloads, and sleep completions.
Concurrent branches awaiting hook.getConflict() preserve their step correlation
IDs when replaying an extended event history.
Failed-run logs include underlying error causes and codes to help diagnose failures such as socket, DNS, and TLS errors. Unreadable causes are marked without preventing the run from being recorded as failed.
Queued step messages carry immutable run identity in runContext, so step
execution skips the initial runs.get and fetches the run row only when
continuing into workflow replay. Messages from older producers without
runContext retain the initial fetch.
When a World advertises capabilities.invoke, resumeHook() sends serialized
hook inputs through world.invoke() and waits for the executor's decision. The
World calls the existing handler with invoke: true, requestId, and the hook
input. Core validates the input, waits for its event write, and returns a
decision. Core shares a run's activity state between workflow execution and these
input calls.
The event write completes before the response is stored. On Worlds with
hookResumeDedup, a stable request identity makes retries reuse the same hook
event, including after hook disposal or run completion. Core can process inputs
while inline steps wait. Workflow code observes committed inputs at replay
boundaries, reusing a retained Node virtual machine when available.
Errors returned by the executor propagate through world.invoke() to the caller
of resumeHook().
Register onRunCompleted and onRunFailed handlers with registerLifecycleHooks
from workflow/api for best-effort reporting of terminal transitions written by
your app. Handlers receive the workflow name without a backend read, a lazy Run
instance, and, for failures, an error hydrated from the persisted payload.
Callbacks are not retried; the event log remains the system of record.
Hook-property getters and reporting failures are isolated from terminal writes.
The callback's waitUntil scope also drains background operations for streams
hydrated from the persisted failure, including when a handler throws.
FAQs
Core runtime and engine for Workflow SDK
The npm package @workflow/core receives a total of 1,155,932 weekly downloads. As such, @workflow/core popularity was classified as popular.
We found that @workflow/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.