
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@xiboplayer/datasource
Advanced tools
Shared data-source cache with dedup, TTL, offline fallback + localStorage persistence for ADA xp:datasource widgets (#235 G9)
Shared data-source cache for ADA xp:datasource widgets (#235 gap G9).
ADA emits xp:datasource="URL" + xp:jsonpath="$.path" on data-bound widgets
(hotel-chain live prices, queue numbers, meeting-room status, bank rates, …).
The translator promotes these into embedded widgets carrying inline JS that
polls the URL. Without a shared cache:
A single DatasourceClient lives in the PWA (not inside each widget iframe):
localStorage so cold boots without network
show yesterday's values instead of blank.meta.stale=true and meta.error set so widgets can render a freshness
badge.postMessage (protocol token xp:datasource), so
cross-origin or blob: URL iframes don't need direct access to the host
client.window.online, all active URLs are force-refreshed.import { DatasourceClient, attachHostBridge, buildWidgetPreamble } from '@xiboplayer/datasource';
// On the host (PWA main.ts):
const client = new DatasourceClient({ defaultRefreshMs: 30_000 });
const bridge = attachHostBridge(client, window);
// window.xpDatasource = client; // optional same-origin escape hatch
// Inline subscribe (same-origin, no iframe):
const unsubscribe = client.subscribe(
'https://tenant.example.com/rooms.json',
(value, meta) => {
document.querySelector('#room-status').textContent = value;
},
{ jsonpath: '$.rooms[0].status', refreshMs: 30_000, fallback: '—' }
);
| Method | Summary |
|---|---|
subscribe(url, cb, opts?) | Register callback; returns unsubscribe fn. Dedup by URL. opts: refreshMs, jsonpath, fallback, persist. |
refresh(url?) | Force a fresh fetch. Omit URL to refresh every active subscription. Returns when the fetch settles. |
peek(url) | Read cached {value, fetchedAt, stale, error} snapshot without subscribing. |
stop() / resume() | Halt or restart pollers (cached values retained). |
stats() | Debug snapshot: {urls, subscriptions, stopped}. |
Installs a message listener. Iframe widgets send:
window.parent.postMessage({
type: 'xp:datasource', action: 'subscribe',
id: 'w1', url: 'https://…', jsonpath: '$.x', refreshMs: 30000, fallback: '—'
}, '*');
The bridge returns values to the originating iframe with
{ type: 'xp:datasource', action: 'value', id, value, stale, error, fetchedAt }.
Send action: 'unsubscribe' to tear down.
Generates a self-contained JS string that the translator
(xiboplayer-smil-tools) can inline in each widget's HTML. The script
subscribes to the configured URL, receives values, and writes them into a
DOM target (default selector [data-xp-bind]). This is the replacement
for the current fetch-loop widget template.
Replace the per-widget setInterval(fetch, 30000) emitter in
src/xlf-builder.js (buildXpTextEmbeddedMedia) with:
import { buildWidgetPreamble } from '@xiboplayer/datasource';
// In the embedded widget HTML:
<script>
${buildWidgetPreamble({
url: item.xpAttrs.datasource,
jsonpath: item.xpAttrs.jsonpath,
refreshMs: parseInt(item.xpAttrs.refresh || '30') * 1000,
fallback: item.xpAttrs.fallback || null,
selector: '[data-xp-bind]',
})}
</script>
<div data-xp-bind></div>
The bundle size stays small (the preamble is a few hundred bytes; all fetch
parseJsonPath + evalJsonPath implement the ADA-emitted subset:
$ root$.a.b.c dot notation$.a[0] / $.a[-1] bracket index (negative = from end)$['a.key'] / $["a key"] quoted bracket keys$.items[*].price wildcard (returns an array)Out of scope (by design): filter expressions [?(@.x>1)], recursive descent
$..name, slices [1:3], script expressions.
cd packages/datasource
pnpm test
Coverage includes: dedup fetching, TTL caching, LKG fallback on error, localStorage persistence, 24-h expiry, stop/resume, JSONPath extraction, widget preamble end-to-end DOM update, host bridge postMessage protocol.
FAQs
Shared data-source cache with dedup, TTL, offline fallback + localStorage persistence for ADA xp:datasource widgets (#235 G9)
The npm package @xiboplayer/datasource receives a total of 0 weekly downloads. As such, @xiboplayer/datasource popularity was classified as not popular.
We found that @xiboplayer/datasource demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.