
Research
/Security News
Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.
This is a pre-release of MLscript.
To install MLscript, you can use npm:
npm i mlscript
The newest version is recommended: there may be lots of bugs in the previous versions.
To watch the project directory, you can use TypeScript(recommended)/JavaScript:
import mlscript from "mlscript"
// filename: string, workDir: string, outputDir: string, tsconfig: string, commonJS: boolean, expectTypeError: boolean
mlscript.watch("./mlscript/Main.mls", "./", "./js/", "./tsconfig.json", false, true)
The path must start with ./, or it will be treated as node_modules paths.
If you need to interoperate with TypeScript, you must provide the path of tsconfig.json file.
Otherwise, it is optional.
You can choose to use CommonJS or ES modules(recommended).
Since Mlscript is still under development, type inferences are not fully supported.
If there is a type error but it is correct, please set the expectTypeError flag to true.
To get the type error messages, please check the corresponding .mlsi files in .interfaces.
For more details, you can check the demo here.
The MLscript uses git to track the file changes.
Please make sure your project locates in a git repo.
Though not necessary, we still recommend you organize the project in this structure:
.interfaces: temporary interface files generated by MLscript.mlscript: directory for MLscript files.node_modules: third-party libraries in TypeScript.ts: directory for TypeScript files.package.json and tsconfig.json should locate in the root directory.FAQs
mlscript
The npm package mlscript receives a total of 2 weekly downloads. As such, mlscript popularity was classified as not popular.
We found that mlscript demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.