
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
devchain-cli
Advanced tools
Quick Start · Remote VMs · Docs · Mobile App · Releases
DevChain runs a team of AI coding agents on your own hardware. Claude Code, Codex, OpenCode, Antigravity, and GitHub Copilot work as coordinated teams, each agent in its own real terminal, with a shared board, chat, and code review.
You describe the work. The agents plan it, build it in parallel, and hand it to you for review. Run them on your PC, or move a project to your own VM and let your laptop sleep.
@mentions, and threads, wired into the agent workflow.
Requirements: Node.js 24 or newer, tmux (brew install tmux / sudo apt install tmux), and at least one provider CLI.
npm install -g devchain-cli
devchain start
DevChain opens in your browser:
teams-dev template: a Planning team (Brainstormer and Architects), a Builders team (Epic Manager and Coders), and a Code Reviewer.devchain start --help lists the port, host, and foreground options. devchain stop stops the server. CI tests DevChain on Linux x64 with Node 24, plus a Node 26 compatibility lane. The install checks that SQLite loads on your platform and stops if it does not; DEVCHAIN_SKIP_POSTINSTALL=1 skips that check.
https://github.com/user-attachments/assets/5ec85c19-f407-43bc-bb44-4da7f899702f
Move a project to your own VM and keep working from the same app. The agents keep running when your laptop sleeps, and the mobile app can tell you when the work is done.
devchain host install). DevChain sets up the VM with itself, the provider CLIs, and the logins you choose.Before you start:
| Provider | CLI |
|---|---|
| Claude Code | claude |
| Codex | codex |
| OpenCode | opencode |
| Antigravity | agy |
| GitHub Copilot | copilot |
Every provider gets live terminal sessions and full transcripts. Model families such as GLM are available through provider configs, and you can switch the provider or model of any agent at any time.
graph LR
Browser["Web UI<br/>(React)"] -->|HTTP + Socket.IO| App["Local App<br/>(NestJS + Fastify)"]
App --> DB[("SQLite<br/>local storage")]
App <-->|tmux / PTY| Sessions["Agent terminal sessions"]
Sessions --- CLIs["Provider CLIs<br/>claude · codex · opencode · agy · copilot"]
CLIs <-->|MCP tools| App
Mobile["Mobile app<br/>(iOS / Android)"] <-->|E2EE relay<br/>sealed data only| App
App <-->|pinned TLS + Syncthing| VM["Remote VM<br/>(DevChain host)"]
The Local App serves the web UI and keeps all state in a local SQLite database. Agents run as provider CLIs in tmux sessions and coordinate through DevChain's MCP tools: epics, chat, reviews, skills, and team management. A Remote VM runs its own DevChain. The Local App sends a connected project's requests to it over TLS pinned to the VM's certificate, and Syncthing keeps the project files in sync over its own encrypted connection. The optional mobile app connects through an end-to-end-encrypted relay that only forwards sealed data it cannot read.
Follow and steer your agent teams from your phone. The app is in open beta on iOS (TestFlight) and Android (Play Store).
Chat with agents, answer their questions as they ask, reassign epics, comment on the board, watch a live terminal, and get a push notification when a session stops or needs you. Review and merge stay on the web. Everything between your PC and your phone is end-to-end encrypted.
Free and source-available under the Elastic License 2.0. You may use, copy, and modify DevChain freely. You may not provide it as a managed service or a competing commercial offering.
FAQs
AI driven development platform
The npm package devchain-cli receives a total of 679 weekly downloads. As such, devchain-cli popularity was classified as not popular.
We found that devchain-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.