
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
The Sellbase CLI installs and maintains Sellbase in your project, whether it is Next.js, Vite + React or any website, on top of your Supabase.
npx supabase start # or pass --supabase-url/--anon-key/--service-role-key/--db-url for a hosted project
npx sellbase create my-store --template nextjs # or --template html: a ready store to start from
npx sellbase init --yes # schema, Edge Functions, store, owner, admin, components, agent files
npx sellbase doctor # checklist with the next step for anything missing
npx sellbase upgrade --dry-run # see what a new version changes
npx sellbase upgrade # backup, migrations, functions, components (your edits are kept)
npx sellbase add product-grid cart-drawer checkout # React storefront components into your repo
npx sellbase seed ropa # example catalog: ropa, curso, consultorio, cafeteria
npx sellbase token create --name "Claude Code" # API token for an AI agent
npx sellbase mcp # MCP server over stdio (init registers it in .mcp.json)
On a local stack, init creates the store owner and writes the admin password to .env.sellbase. For hosted projects, pass --owner-email to send an invitation.
Part of Sellbase, open source commerce that lives inside your project. MIT licensed.
FAQs
Add commerce to any app your AI builds: `npx sellbase init`.
The npm package sellbase receives a total of 680 weekly downloads. As such, sellbase popularity was classified as not popular.
We found that sellbase demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.