
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
Twilio alternative for developers. Send SMS, OTP codes, and verification messages from your terminal through your own Android phone. Free 5-day trial at sms8.io, then $29/mo unlimited. No per-SMS fees, no A2P 10DLC, no markups. CLI for scripts, cron, CI,
sms8 is a zero-dependency CLI that sends SMS, generates and verifies OTP codes, and reads your SMS inbox — routed through your own Android phone instead of Twilio. One command. No CPaaS account. No A2P 10DLC paperwork. $29/month flat for unlimited messages.
npx sms8-cli send +14155550100 "Welcome aboard!"
That's it. The SMS leaves your real mobile number and arrives in the recipient's regular SMS app.
sms8-cli# One-off use
npx sms8-cli send +14155550100 "Hello"
# Or install globally
npm install -g sms8-cli
sms8 send +14155550100 "Hello"
Node 18 or newer.
Set it once:
export SMS8_API_KEY=sk_xxx
# or
sms8 config set api_key=sk_xxx
sms8 send +14155550100 "Order #1234 shipped — track at example.com/t/1234"
By default SMS8 picks your primary paired Android. To pin a specific phone or SIM slot:
# Specific device
sms8 send +14155550100 "Hi" --device-id=10700
# Device + SIM 2 (dual-SIM Android)
sms8 send +14155550100 "Hi" --device-id=10700 --sim-slot=2
# Explicit list (each entry is deviceID or deviceID|simSlot)
sms8 send +14155550100 "Hi" --devices=10700,10701|0
# Broadcast across all paired devices
sms8 send +14155550100 "Status update" --option=1
# Broadcast across all SIMs of all paired devices
sms8 send +14155550100 "Status update" --option=2
# Pick a random device from the resolved list (load-balancing)
sms8 send +14155550100 "Hi" --random-device
Run sms8 devices to see your paired devices and their IDs.
sms8 otp send +14155550100
# → 6-digit code arrives on the user's phone
OTP options (length, expiry, template, routing — all optional):
sms8 otp send +14155550100 --length=8 --expires-in=180
sms8 otp send +14155550100 --template="Your YourApp code: {code}"
sms8 otp send +14155550100 --device-id=10700 --sim-slot=2
sms8 otp verify +14155550100 482937
# → { "verified": true }
verify_otp checks the most-recent unverified code for that phone — no device routing
needed because the code lives server-side, not on a specific SIM.
wait watches incoming SMS on a paired Android and pulls out the verification code.
Pass the sender's phone or shortcode (or part of it):
# Wait for any code sent from a Google number
CODE=$(sms8 otp wait +Google --timeout=180 --contains="Google")
# Wait for a code from a specific E.164 number, only on device 10700
CODE=$(sms8 otp wait +12025550100 --timeout=120 --device-id=10700)
# 8-digit code only (some banks)
CODE=$(sms8 otp wait +YourBank --code-min-length=8 --code-max-length=8 --timeout=300)
echo "Got code: $CODE"
sms8 inbox --limit=10
sms8 inbox --received --limit=20
sms8 inbox --sent --limit=20
sms8 inbox --phone=+14155550100 # filter to one conversation
sms8 devices # shows IDs to use with --device-id
sms8 balance
sms8 setup
read -p "Phone (E.164): " PHONE
sms8 otp send "$PHONE"
read -p "Code: " CODE
if sms8 otp verify "$PHONE" "$CODE" | grep -q '"verified": true'; then
echo "Welcome!"
else
echo "Wrong code."
fi
# Trigger a transactional SMS in your app
curl -X POST https://your.app/trigger-otp -d 'phone=+14155550100'
# Wait for the code to arrive on the test SIM
CODE=$(sms8 otp wait +14155550100 --timeout=180)
echo "Code received: $CODE"
# Submit it to your app
curl -X POST https://your.app/verify -d "phone=+14155550100&code=$CODE"
Your Android phone runs the free SMS8 app and stays online. Each sms8 command POSTs to the SMS8 cloud, which queues the message; your phone polls, sends the SMS over its real SIM, and reports back. Round-trip is typically under 4 seconds.
Want your AI assistant to send SMS directly? Use the companion package sms8-mcp — it exposes the same tools to any Model Context Protocol client.
{
"mcpServers": {
"sms8": {
"command": "npx",
"args": ["-y", "sms8-mcp"],
"env": { "SMS8_API_KEY": "sk_xxx" }
}
}
}
Full docs at mcp.sms8.io.
MIT
FAQs
Twilio alternative for developers. Send SMS, OTP codes, and verification messages from your terminal through your own Android phone. Free 5-day trial at sms8.io, then $29/mo unlimited. No per-SMS fees, no A2P 10DLC, no markups. CLI for scripts, cron, CI,
The npm package sms8-cli receives a total of 11 weekly downloads. As such, sms8-cli popularity was classified as not popular.
We found that sms8-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.