A collection of MIT-licensed extensions, skills, and themes for Pi, an AI coding agent for the terminal. Features include a leader-key palette, semantic git review, session management, custom status bar, and tool integrations designed to work individually or together.
A security researcher identified 40 malicious Chrome extensions collectively installed by approximately 21.9 million users, documenting capabilities including credential theft, traffic exfiltration, affiliate link injection, and undisclosed data collection. The analysis found 7 extensions actively transmitting data and 33 containing malicious code not observed firing during testing, with common offenses including full-URL exfiltration, fingerprinting, and unauthorized telemetry.
Reddit is blocking access on Firefox for Android when uBlock Origin is enabled, displaying an error message that prompts users to disable extensions or switch browsers. This follows Reddit's earlier decision to block old.reddit.com for unsigned-out users.
Vivaldi 8.2 for mobile introduces support for third-party extensions on Android and iOS, allowing users to access Chrome Web Store add-ons directly from the Address Bar. The update also brings a built-in Address Bar Calculator to mobile devices, enabling quick calculations without switching apps.
A 15-year-old Chrome Web Store developer account was suddenly suspended and its extensions flagged as malware despite no code changes in over a year and prior manual CWS approval. The automated malware warning is now displayed to users, causing reputational damage while the developer awaits manual review of their appeal.
A user questions why Google allows browser extensions that use ExtPay, a third-party payment script, citing security concerns after discovering it in a cursor-sparkle extension on the Chrome Web Store.
The SponsorBlock Firefox extension developer argues that new mandatory data transmission permission declarations are misleading and confusing. The extension uses privacy-preserving K-Anonymity to fetch sponsorship data without transmitting watched videos, but Mozilla's requirements force declarations that incorrectly categorize it alongside malicious extensions, causing user distrust and conspiracy theories during updates.
A Chrome Web Store developer with a 15-year history reports sudden account suspension and malware warnings for their Magic Actions extension, despite no code changes in over a year and prior manual CWS approval. The developer suspects an automated false positive and reports widespread user panic from Chrome's malware warnings, with an appeal submitted but no confirmation received.