
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
devchain-cli
Advanced tools
AI agent orchestration platform for software development teams
Homepage · Quick Start Guides · What's New in v0.12.0
Devchain runs your AI coding agents as coordinated teams — each with their own terminal session, task queue, and chat. Group agents under team leads, assign epics, track progress on a visual board, and let teams scale themselves to match the workload. Supports Claude Code, Codex, Gemini CLI, and OpenCode out of the box.
Group agents into named teams with team leads that do real management. The Builders team grows itself with the workload and picks the right model for each task — cheaper models for routine changes, top-tier models for harder work. The Planning team supports parallel planning: add multiple Architects on different models and the Brainstormer gathers independent framings from each before drafting the master plan. Choose your allowed providers per team when you create the project.
Full transcript viewer for active agent sessions, built into the Chat page. See every tool call, thinking block, and response with real-time token usage, cost tracking, and compaction events. Supports Claude Code and Codex transcripts with AI turn grouping, collapsible cards, IQR-based token hotspot detection, and keyboard navigation.
Visual progress bars show each agent's context window usage in real time. Hover for exact token counts (e.g. "49% used — 98k of 200k"). An inline session summary bar in each terminal shows the active model, running cost, context percentage, and compaction count at a glance.
Change any agent's provider and model on the fly from the context menu — no template editing required. Model overrides are per-agent and persist across restarts, layering on top of template defaults.
Spin up isolated agent environments on dedicated git branches. Each worktree gets its own agent team, terminals, and chat — run multiple features in parallel and merge when ready. Worktrees run as Docker containers or local processes with full branch isolation.
Worktree containers are provisioned automatically from the official Devchain image on GHCR. Each container has Claude Code, Codex, and Gemini CLI pre-installed, runs as a non-root user, and shares your git identity for correct commit attribution.
Browse and sync AI agent skills from community sources (Anthropic, OpenAI, Vercel, and more). Enable or disable skills per project and expose them to agents via MCP tools.
Kanban-style epic management with drag-and-drop, list view, board context menu, and URL-based filtering. Agents pick up tasks from the board and update status in real time.
Real terminal streaming via tmux and WebSocket. Each agent gets its own session with scrollback, resize support, and inline access from the chat panel.
Live pre-commit diff viewer with agent integration, inline comments, @mentions, comment threading, and VS Code-style file navigation.
Works with Claude Code, OpenAI Codex, Google Gemini CLI, GLM models, and OpenCode. Switch providers per agent or switch the whole team preset with a single click.
Full Model Context Protocol support. Agents get access to epics, chat, skills, reviews, and more through MCP tools — auto-configured before each session.
All data stored in a local SQLite database. No cloud account required, no data leaving your machine.
brew install tmuxsudo apt install tmuxnpm install -g devchain-cli
# Start Devchain — opens browser automatically
devchain start
# Start with a specific project
devchain start --project /path/to/your/project
# Run in foreground with logs
devchain start --foreground
# Bind to all interfaces for VM/remote browser access
devchain start --host 0.0.0.0
# Stop the server
devchain stop
On first run, import a template from the project page to provision your agent team. Three templates are included:
| Template | Agents | Best for |
|---|---|---|
teams-dev (recommended) | Planning team (Brainstormer + Architect), Builders team (Epic Manager + Coders), Code Reviewer | New projects — auto-scaling Builders, parallel planning, tier-aware routing |
5-agents-dev | Brainstormer, Epic Manager, SubBSM, Coder, Code Reviewer | The classic flat workflow (still bundled and supported) |
3-agents-dev | Brainstormer, SubBSM, Coder | Faster iteration with lower token overhead |
| Option | Description |
|---|---|
-p, --port <number> | Port to run on (default: 3000 or next available) |
--host <address> | Bind address (default: 127.0.0.1; use 0.0.0.0 for remote/VM access — see docs/setup.md) |
-f, --foreground | Run in foreground with visible logs |
--no-open | Don't open browser automatically |
--db <path> | Custom database directory path |
--project <path> | Open with a specific project path |
Elastic License 2.0 — Free to use. You may not provide this software as a managed service or competing commercial offering.
FAQs
AI driven development platform
The npm package devchain-cli receives a total of 679 weekly downloads. As such, devchain-cli popularity was classified as not popular.
We found that devchain-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.