
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
claude-to-opencode
Advanced tools
Keep Claude Code memory and PreToolUse or PostToolUse command guardrails when moving to OpenCode. Dry run first.
Switch to OpenCode without losing Claude Code memory or command guardrails.
npx claude-to-opencode
npx claude-to-opencode --apply
The first command is a dry run. It shows the exact destinations and everything that stays manual.
To install only the hook bridge into an existing OpenCode setup, run this instead.
npx claude-to-opencode --hooks-only
npx claude-to-opencode --hooks-only --apply
Existing Bash blockers, secret checks, and edit-time linters continue to run from the original Claude settings.
It handles the current project's auto memory, global and project instructions, unconditional rules, commands, subagents, local or remote MCP servers, and PreToolUse or PostToolUse command hooks. Auto memory stays in its Claude directory and is referenced by OpenCode, so later updates remain visible. Hook commands stay in Claude settings and run through a generated OpenCode plugin. OpenCode reads Claude skills directly, so the command leaves those files in place. Existing destinations and secret-looking plaintext values are not copied.
Path-scoped Claude rules, other hook events and hook types, permissions, and sessions stay manual because OpenCode does not give them the same semantics.
The implementation and safety tests live in dsh-movein. The separate opencode-claude-code-hooks package runs supported Claude Code command hooks directly in OpenCode.
FAQs
Keep Claude Code memory and PreToolUse or PostToolUse command guardrails when moving to OpenCode. Dry run first.
We found that claude-to-opencode demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.