
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@workflow/world-local
Advanced tools
Filesystem-based workflow backend for local development and testing.
Stores workflow data as JSON files on disk and provides in-memory queuing. Automatically detects development server port for queue transport.
Used by default on next dev and next start.
The local World continues to resume hooks by writing an event and queuing
workflow execution. It does not implement world.invoke() or enable
capabilities.invoke.
Concurrent creation of the same hook across storage instances sharing a data
directory publishes one hook_created event. A losing creator reports an
entity conflict without appending another creation, including when a retry
publishes before the original token-claim owner.
Its HTTP queue handler supports receiving invoke: true messages and returns
the callback's value as { result }. For example, a callback returning
{ timeoutSeconds: 5 } produces { result: { timeoutSeconds: 5 } }. The value is
response data; the receiver does not schedule another execution for that
invocation.
import { createWorld } from '@workflow/world-local';
const world = createWorld({
dataDir: './custom-workflow-data',
});
FAQs
Local development World implementation for Workflow SDK
The npm package @workflow/world-local receives a total of 1,265,587 weekly downloads. As such, @workflow/world-local popularity was classified as popular.
We found that @workflow/world-local demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.