
Research
/Security News
77 Firefox Extensions Linked to Crypto Wallet and Credential Theft
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.
@zeroheight/adoption-cli
Advanced tools
CLI for measuring component usage to view in your zeroheight account.
See release notes here
npm i @zeroheight/adoption-cli
In the repository in which you wish to analyze the component usage, run the following command:
zh-adoption analyze
-e / --extensions
Provide a glob pattern to search for files with a specific extension.
zh-adoption analyze -e "**/*.{js,jsx,ts,tsx}"
-i / --ignore
Provide a glob pattern to ignore files, directories or file extensions when searching for components.
zh-adoption analyze -i "**/*.{test,spec}.*"
-r / --repo-name
Provide a name for the current repository. This must be passed when -in / --interactive is set to false.
zh-adoption analyze -r "My Repo"
-in / --interactive
Pass in false to disable the interactive mode e.g. when running in a CI environment.
zh-adoption analyze --interactive false -r "My Repo"
To send adoption data to your zeroheight account you will need to authenticate using a Client ID and Access Token.
When running the analyze command, you will be prompted to authenticate. This will save the Client ID and Access Token to your local machine.
Alternatively, you can authenticate by running the following command:
zh-adoption auth
When running the analyze command with the --interactive false flag, you will need to provide the Client ID and Access Token as environment variables.
export ZEROHEIGHT_CLIENT_ID="your-client-id"
export ZEROHEIGHT_ACCESS_TOKEN="your-access-token"
More info on the commands can be seen by running
zh-adoption --help
FAQs
CLI for measuring component usage
The npm package @zeroheight/adoption-cli receives a total of 5,039 weekly downloads. As such, @zeroheight/adoption-cli popularity was classified as popular.
We found that @zeroheight/adoption-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.

Security News
NIST disclosed an unreleased AI tool called V-etalon and opened a broad inquiry into NVD modernization after years of automation plans produced no public enrichment system.

Security News
In his AI Council 2026 talk, Feross Aboukhadijeh covers recent package compromises, vulnerability discovery, and a more automated security model.