
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
engrm-openclaw-plugin
Advanced tools
Native OpenClaw integration for Engrm.
Engrm gives OpenClaw shared memory across devices, sessions, and agents. The same memory layer can be reused across OpenClaw, Claude Code, and Codex.
/engrm command with connect, status, and disconnectengrm_statusengrm_connectengrm_recentengrm_searchengrm_delivery_reviewopenclaw plugins install engrm-openclaw-plugin
Then restart OpenClaw or the OpenClaw gateway.
If the plugin is already installed, update it in place instead of reinstalling:
openclaw plugins update engrm
To update all npm-installed plugins at once:
openclaw plugins update --all
OpenClaw tracks npm-installed plugins and updates them cleanly once the first install has happened.
In an OpenClaw chat:
/engrm connect
That opens browser auth and links the current OpenClaw machine to your Engrm account.
You can verify with:
/engrm status
FAQs
Native Engrm shared memory plugin for OpenClaw
The npm package engrm-openclaw-plugin receives a total of 4 weekly downloads. As such, engrm-openclaw-plugin popularity was classified as not popular.
We found that engrm-openclaw-plugin demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.