
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
A CLI to enhance your next.js dev environment for agents
git clone git@github.com:vercel/xtra.git
cd xtra
./install-local.sh
try in a next.js
pnpx create-next-app@latest xtra-test --yes
cd my-app
xtra init
xtra
USAGE
xtra <command> [options]
COMMANDS
init Initialize xtra in your Next.js app
test Run all *.test.{ts,tsx,js,jsx} files in browser
exec <code> Execute TypeScript/JavaScript in browser
screenshot Capture screenshots of your app
dev Start Next.js development server
docs Search Next.js documentation
logs View browser + server console logs
network View network requests made in browser
replay View sequence of events representing what you did in the browser
ports Manage active dev servers
prompts Manage rule files optimized for next.js
agents Manage specialized agent configs for next.js
OPTIONS
--help, -h Show this help message
--version, -v Show version number
EXAMPLES
xtra init
xtra test
xtra exec "import * as React from 'react'; console.log(React.version)"
xtra exec "console.log(process.pid)" --server
xtra screenshot --selector="#app" --filename="my-screenshot"
xtra logs --follow
xtra network --summary
xtra replay --follow
xtra dev --turbopack --port=3001
xtra ports --kill=3000
Run xtra <command> --help for detailed command options
cd xtra
./install-dev.sh
Then inside any next.js app:
xtra-dev watch
Any changes made to the template dir inside the xtra repo will automatically sync the next.js project.
Use the xtra-dev command to reference the non compiled files in the project. xtra will reference the binary inside xtra/bin.
Note: the CLI is ran with bun, so there is no build step for non template code during development
FAQs
A CLI to enhance your next.js dev environment for agents
The npm package xtra receives a total of 0 weekly downloads. As such, xtra popularity was classified as not popular.
We found that xtra demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.