|
Malicious Chrome Extension Injects Hidden SOL Fees Into Solana Swaps
|
Kush Pandya |
2025-11-25 |
1,517 |
--
|
|
PyPI Expands Trusted Publishing to GitLab Self-Managed as Adoption Passes 25 Percent
|
Sarah Gooding |
2025-11-14 |
644 |
--
|
|
ENISA’s 2025 Threat Landscape: AI Reshapes Cyber Attacks, from Phishing to Supply …
|
Sarah Gooding |
2025-10-16 |
680 |
--
|
|
The Nightmare Before Deployment
|
Ahmad Nassri |
2025-12-16 |
603 |
--
|
|
Another Round of TEA Protocol Spam Floods npm, But It’s Not a …
|
Philipp Burckhardt |
2025-11-14 |
929 |
--
|
|
Introducing Webhook Events for Pull Request Scans
|
Jeppe Hasseriis |
2025-10-22 |
539 |
--
|
|
Malicious Chrome Extensions “Phantom Shuttle” Masquerade as a VPN to Intercept Traffic …
|
Kush Pandya |
2025-12-22 |
2,864 |
--
|
|
Malicious NuGet Package Typosquats Popular .NET Tracing Library to Steal Wallet Passwords
|
Kirill Boychenko |
2025-12-15 |
1,996 |
--
|
|
Unify Your Security Stack with Socket Basics
|
Douglas Coburn and Eli Insua |
2025-10-21 |
1,150 |
--
|
|
Engineering with AI Podcast: The Promise of AI-First Development
|
Sarah Gooding |
2025-12-24 |
12,951 |
--
|
|
2025 Report: Destructive Malware in Open Source Packages
|
Kush Pandya |
2025-12-24 |
1,393 |
--
|
|
Ruby Central Faces Backlash After Publishing Incident Timeline on RubyGems Access Dispute
|
Sarah Gooding |
2025-10-14 |
2,204 |
--
|
|
Deno 2.6 + Socket: Supply Chain Defense In Your CLI
|
Sarah Gooding |
2025-12-12 |
520 |
--
|
|
npm Malware Campaign Uses Adspect Cloaking to Deliver Malicious Redirects
|
Olivia Brown |
2025-11-17 |
3,290 |
--
|
|
Announcing Experimental Malware Scanning for the Hugging Face Ecosystem
|
Wenxin Jiang |
2025-10-20 |
1,597 |
--
|
|
Critical Security Vulnerability in React Server Components
|
Sarah Gooding |
2025-12-03 |
395 |
--
|
|
Inside the GitHub Infrastructure Powering North Korea’s Contagious Interview npm Attacks
|
Kirill Boychenko |
2025-11-26 |
5,010 |
--
|
|
Malicious Go Packages Impersonate Google’s UUID Library and Exfiltrate Data
|
Kirill Boychenko |
2025-12-05 |
2,004 |
--
|
|
New CNAPulse Dashboard Tracks CNA Activity and Disclosure Trends
|
Sarah Gooding |
2025-10-24 |
580 |
--
|
|
Announcing Bun and vlt Support in Socket
|
Ricky Reusser and Eli Insua |
2025-11-19 |
687 |
--
|
|
Scaling Socket from Zero to 10,000+ Organizations
|
Sarah Gooding |
2025-12-02 |
185 |
--
|
|
North Korea’s Contagious Interview Campaign Escalates: 338 Malicious npm Packages, 50,000 Downloads
|
Kirill Boychenko |
2025-10-10 |
3,160 |
--
|
|
Malicious Rust Crate evm-units Serves Cross-Platform Payloads for Silent Execution
|
Olivia Brown |
2025-12-02 |
1,645 |
--
|
|
Announcing Socket Certified Patches: One-Click Fixes for Vulnerable Dependencies
|
Mikola Lysenko, Jordan Harband and Jonah Ghebremichael |
2025-11-18 |
1,420 |
--
|
|
131 Spamware Extensions Targeting WhatsApp Flood Chrome Web Store
|
Kirill Boychenko |
2025-10-18 |
2,418 |
--
|
|
npm Sees Surge of Auto-Generated “elf-stats” Packages Published Every Two Minutes
|
Olivia Brown |
2025-12-03 |
7,848 |
--
|
|
Malicious NuGet Packages Typosquat Nethereum to Exfiltrate Wallet Keys
|
Kirill Boychenko |
2025-10-22 |
1,487 |
--
|
|
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
|
Kush Pandya |
2025-11-06 |
2,255 |
--
|
|
The Changelog Podcast: Practical Steps to Stay Safe on npm
|
Sarah Gooding |
2025-10-31 |
429 |
--
|
|
Vite+ Joins the Push to Consolidate JavaScript Tooling
|
Sarah Gooding |
2025-10-15 |
551 |
--
|
|
How Enterprise Security Is Adapting to AI-Accelerated Threats
|
Sarah Gooding |
2025-11-04 |
267 |
--
|
|
Introducing Socket Firewall Enterprise: Flexible, Configurable Protection for Modern Package Ecosystems
|
Bradley Meck Farias and Dale Bustad |
2025-10-24 |
770 |
--
|
|
npm Revokes Classic Tokens, as OpenJS Warns Maintainers About OIDC Gaps
|
Sarah Gooding |
2025-12-10 |
1,318 |
--
|
|
ENISA Becomes a CVE Root, Expanding Its Role in Europe’s Vulnerability Ecosystem
|
Sarah Gooding |
2025-11-21 |
566 |
--
|
|
Spearphishing Campaign Abuses npm Registry to Target U.S. and Allied Manufacturing and …
|
Nicholas Anderson and Kirill Boychenko |
2025-12-23 |
2,631 |
--
|
|
Rust RFC Proposes a Security Tab on crates.io for RustSec Advisories
|
Sarah Gooding |
2025-12-09 |
1,073 |
--
|
|
November CVEs Fell 25% YoY, Driven by Slowdowns at Major CNAs
|
Sarah Gooding |
2025-12-04 |
596 |
--
|
|
TypeScript 6.0 Will Be the Last JavaScript-Based Major Release
|
Sarah Gooding |
2025-12-03 |
853 |
--
|
|
Socket Firewall Now Available in Docker Hardened Images
|
Sarah Gooding |
2025-12-17 |
504 |
--
|
|
New React Server Components Vulnerabilities: DoS and Source Code Exposure
|
Sarah Gooding |
2025-12-12 |
388 |
--
|
|
Introducing Webhook Events for Alert Changes
|
Phil Gates-Idem |
2025-11-21 |
728 |
--
|
|
Shai Hulud Strikes Again (v2)
|
Socket Research Team |
2025-11-24 |
3,910 |
--
|
|
Meet Socket at Black Hat Europe and BSides London 2025
|
Anders Søndergaard |
2025-11-11 |
338 |
--
|
|
Malicious Chrome Extension Exfiltrates Seed Phrases, Enabling Wallet Takeover
|
Kirill Boychenko |
2025-11-12 |
1,371 |
--
|
|
Introducing Socket Scanning for OpenVSX Extensions
|
Mix Irving and Ryan Eberhardt |
2025-11-20 |
954 |
--
|
|
175 Malicious npm Packages Host Phishing Infrastructure Targeting 135+ Organizations
|
Kush Pandya |
2025-10-09 |
2,193 |
--
|
|
Reachability for Ruby Now in Beta
|
Oskar Haarklou Veileborg |
2025-11-17 |
572 |
--
|
|
Malicious Crate Mimicking ‘Finch’ Exfiltrates Credentials via a Hidden Dependency
|
Kush Pandya |
2025-12-05 |
1,650 |
--
|
|
Software Engineering Daily Podcast: Feross on AI, Open Source, and Supply Chain …
|
Sarah Gooding |
2025-12-11 |
10,160 |
--
|
|
Socket Integrates With Bun 1.3’s Security Scanner API
|
Ahmad Nassri and Bradley Meck Farias |
2025-10-10 |
691 |
--
|
|
Ruby Core Team Assumes Stewardship of RubyGems and Bundler, Former Maintainers Offer …
|
Sarah Gooding |
2025-10-29 |
1,352 |
--
|
|
OWASP 2025 Top 10 Adds Software Supply Chain Failures, Ranked Top Community …
|
Sarah Gooding |
2025-11-08 |
896 |
--
|
|
10 npm Typosquatted Packages Deploy Multi-Stage Credential Harvester
|
Kush Pandya |
2025-10-28 |
2,559 |
--
|
|
Security Community Slams MIT-linked Report Claiming AI Powers 80% of Ransomware
|
Sarah Gooding |
2025-10-30 |
1,140 |
--
|
|
Weaponizing Discord for Command and Control Across npm, PyPI, and RubyGems.org
|
Olivia Brown |
2025-10-11 |
1,952 |
--
|
|
Google’s OSV Fix Just Added 500+ New Advisories — All Thanks to …
|
Jonathan Leitschuh |
2025-10-10 |
940 |
--
|
|
Introducing GitHub Actions Scanning Support
|
Rakesh Chatrath and Greg Tystahl |
2025-10-23 |
806 |
--
|
|
npm to Implement Staged Publishing After Turbulent Shift Off Classic Tokens
|
Sarah Gooding |
2026-01-07 |
1,310 |
--
|
|
GitHub Actions Pricing Whiplash: Self-Hosted Actions Billing Change Postponed
|
Sarah Gooding |
2026-01-05 |
1,672 |
--
|
|
Tailwind CSS Announces 75% Layoffs as LLMs Reshape OSS Business Models
|
Sarah Gooding |
2026-01-08 |
1,595 |
--
|
|
Malicious Chrome Extension Steals MEXC API Keys for Account Takeover
|
Kirill Boychenko |
2026-01-12 |
2,448 |
--
|
|
Insecure Agents Podcast: Certified Patches, Supply Chain Security, and AI Agents
|
Sarah Gooding |
2026-01-08 |
339 |
--
|
|
CVE Volume Surges Past 48,000 in 2025 as WordPress Plugin Ecosystem Drives …
|
Sarah Gooding |
2026-01-09 |
785 |
--
|
|
Node.js Fixes AsyncLocalStorage Crash Bug That Could Take Down Production Servers
|
Sarah Gooding |
2026-01-14 |
1,050 |
--
|
|
Rust Support in Socket Is Now Generally Available
|
Trevor Norris |
2026-01-19 |
562 |
--
|
|
Temporal API Ships in Chrome 144, Marking a Major Shift for JavaScript …
|
Sarah Gooding |
2026-01-16 |
640 |
--
|
|
5 Malicious Chrome Extensions Enable Session Hijacking in Enterprise HR and ERP …
|
Kush Pandya |
2026-01-15 |
3,972 |
--
|
|
Introducing Custom Tabs for Org Alerts
|
André Staltz |
2026-01-20 |
436 |
--
|
|
Introducing Immutable Scans
|
Nolan Lawson |
2026-01-23 |
804 |
--
|
|
Introducing Supply Chain Attack Campaigns Tracking in the Socket Dashboard
|
Philipp Burckhardt |
2026-01-21 |
759 |
--
|
|
curl Shuts Down Bug Bounty Program After Flood of AI Slop Reports
|
Sarah Gooding |
2026-01-23 |
1,027 |
--
|
|
Introducing the Alert Details Page: A Better Way to Explore Alerts
|
André Staltz |
2026-01-22 |
512 |
--
|
|
PyPI Package Impersonates SymPy to Deliver Cryptomining Malware
|
Kirill Boychenko |
2026-01-21 |
1,669 |
--
|
|
Node.js 25.4.0 Ships with Stable require(esm)
|
Sarah Gooding |
2026-01-21 |
591 |
--
|
|
crates.io Ships Security Tab and Tightens Publishing Controls
|
Sarah Gooding |
2026-01-27 |
812 |
--
|
|
Malicious Chrome Extension Performs Hidden Affiliate Hijacking
|
Kush Pandya |
2026-01-27 |
1,426 |
--
|
|
Federal Government Rescinds Software Supply Chain Mandates, Makes SBOMs Optional
|
Sarah Gooding |
2026-01-28 |
541 |
--
|
|
n8n Tops 2025 JavaScript Rising Stars as Workflow Platforms Gain Momentum
|
Sarah Gooding |
2026-01-29 |
789 |
--
|
|
GlassWorm Loader Hits Open VSX via Developer Account Compromise
|
Kirill Boychenko |
2026-01-31 |
2,317 |
--
|
|
Inside Lodash’s Security Reset and Maintenance Reboot
|
Sarah Gooding |
2026-01-31 |
1,528 |
--
|
|
Open VSX Begins Implementing Pre-Publish Security Checks After Repeated Supply Chain Incidents
|
Sarah Gooding |
2026-02-02 |
811 |
--
|
|
gem.coop Tests Dependency Cooldowns as Package Ecosystems Move to Slow Down Attacks
|
Sarah Gooding |
2026-02-05 |
444 |
--
|
|
Malicious dYdX Packages Published to npm and PyPI After Maintainer Compromise
|
Kush Pandya |
2026-02-06 |
2,458 |
--
|
|
The Next Open Source Security Race: Triage at Machine Speed
|
Sarah Gooding |
2026-02-06 |
1,361 |
--
|
|
AI Agent Submits PR to Matplotlib, Publishes Angry Blog Post After Rejection
|
Sarah Gooding |
2026-02-12 |
1,959 |
--
|
|
Cline CLI npm Package Compromised via Suspected Cache Poisoning Attack
|
Sarah Gooding |
2026-02-18 |
1,079 |
--
|
|
Four Malicious NuGet Packages Target ASP.NET Developers With JIT Hooking and Credential …
|
Kush Pandya |
2026-02-23 |
3,466 |
--
|
|
Malicious Chrome Extension Steals Meta Business Manager Exports and TOTP 2FA Seeds
|
Kirill Boychenko |
2026-02-13 |
2,621 |
--
|
|
Socket Joins the OpenJS Foundation
|
Sarah Gooding |
2026-02-19 |
414 |
--
|
|
SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflows and Poisons AI Toolchains
|
Socket Research Team |
2026-02-20 |
7,183 |
--
|
|
AI Agent Lands PRs in Major OSS Projects, Targets Maintainers via Cold …
|
Sarah Gooding |
2026-02-14 |
1,922 |
--
|
|
Socket Brings Supply Chain Security to skills.sh
|
Wenxin Jiang and Alexandros Kapravelos |
2026-02-17 |
701 |
--
|
|
High-Severity RCE Vulnerability Disclosed in next-mdx-remote
|
Sarah Gooding |
2026-02-12 |
630 |
--
|
|
Introducing PHP and Composer Support in Socket
|
Trevor Norris |
2026-02-17 |
980 |
--
|
|
OpenClaw Skill Marketplace Emerges as Active Malware Vector
|
Sarah Gooding |
2026-02-09 |
1,205 |
--
|
|
Socket Security Analysis Is Now One Click Away on npm
|
Sarah Gooding |
2026-02-19 |
474 |
--
|
|
npm Introduces minimumReleaseAge and Bulk OIDC Configuration
|
Sarah Gooding |
2026-02-26 |
669 |
--
|
|
Risky Biz Podcast: Open Source Risk Is Compounding as AI Agents Write …
|
Sarah Gooding |
2026-02-24 |
222 |
--
|
|
Malicious Go “crypto” Module Steals Passwords and Deploys Rekoobe Backdoor
|
Kirill Boychenko |
2026-02-26 |
2,254 |
--
|
|
StegaBin: 26 Malicious npm Packages Use Pastebin Steganography to Deploy Multi-Stage Credential …
|
Philipp Burckhardt and Peter van der Zee |
2026-02-27 |
4,377 |
--
|
|
minimatch Patches 3 High-Severity ReDoS Vulnerabilities
|
Sarah Gooding |
2026-02-28 |
729 |
--
|
|
Unauthorized AI Agent Execution Code Published to OpenVSX in Aqua Trivy VS …
|
Peter van der Zee and Philipp Burckhardt |
2026-03-02 |
3,627 |
--
|
|
Meet the Socket Team at RSAC and BSidesSF 2026
|
Sarah Gooding |
2026-03-03 |
415 |
--
|
|
Malicious Packagist Packages Disguised as Laravel Utilities Deploy Encrypted RAT
|
Kush Pandya |
2026-03-03 |
1,593 |
--
|
|
Socket Named a Supply Chain Innovator in Latio's 2026 Application Security Market …
|
Sarah Gooding |
2026-03-05 |
461 |
--
|
|
Fake imToken Chrome Extension Steals Seed Phrases via Phishing Redirects
|
Kirill Boychenko |
2026-03-05 |
1,877 |
--
|
|
OpenClaw Advisory Surge Highlights Gaps Between GHSA and CVE Tracking
|
Sarah Gooding |
2026-03-10 |
1,307 |
--
|
|
5 Malicious Rust Crates Posed as Time Utilities to Exfiltrate .env Files
|
Kirill Boychenko |
2026-03-10 |
1,741 |
--
|
|
Node.js Moves to Annual Major Releases Starting with Node 27
|
Sarah Gooding |
2026-03-11 |
981 |
--
|
|
GCVE Launches Decentralized Publishing Ecosystem for Vulnerability Disclosure
|
Sarah Gooding |
2026-03-12 |
1,103 |
--
|
|
6 Malicious Packagist Themes Ship Trojanized jQuery and FUNNULL Redirect Payloads
|
Kush Pandya |
2026-03-12 |
2,517 |
--
|
|
72 Malicious Open VSX Extensions Linked to GlassWorm Campaign Now Using Transitive …
|
Socket Research Team |
2026-01-31 |
1,820 |
--
|
|
TC39 Advances Temporal to Stage 4 Alongside Several ECMAScript Proposals
|
Sarah Gooding |
2026-03-16 |
706 |
--
|
|
GlassWorm Sleeper Extensions Activate on Open VSX, Shift to GitHub-Hosted VSIX Malware
|
Philipp Burckhardt and Peter van der Zee |
2026-03-18 |
3,676 |
--
|
|
ENISA Publishes Technical Advisory on Secure Use of Package Managers
|
Sarah Gooding |
2026-03-19 |
862 |
--
|
|
Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets
|
Philipp Burckhardt |
2026-03-20 |
3,346 |
--
|
|
CanisterWorm: npm Publisher Compromise Deploys Backdoor Across 29+ Packages
|
Socket Research Team |
2026-03-20 |
1,361 |
--
|
|
Trivy Supply Chain Attack Expands to Compromised Docker Images
|
Philipp Burckhardt |
2026-03-22 |
366 |
--
|
|
TeamPCP Is Systematically Targeting Security Tools Across the OSS Ecosystem
|
Sarah Gooding |
2026-03-24 |
886 |
--
|
|
TypeScript 6.0 Released: The Final JavaScript-Based Version
|
Sarah Gooding |
2026-03-23 |
637 |
--
|
|
5 Malicious npm Packages Typosquat Solana and Ethereum Libraries to Steal Private …
|
Kush Pandya |
2026-03-24 |
1,691 |
--
|
|
Widespread GitHub Campaign Uses Fake VS Code Security Alerts to Deliver Malware
|
Sarah Gooding and Peter van der Zee |
2026-03-25 |
1,127 |
--
|
|
TeamPCP Compromises Telnyx Python SDK to Deliver Credential-Stealing Malware
|
Socket Research Team |
2026-03-27 |
3,756 |
--
|
|
TeamPCP Partners With Ransomware Group Vect to Target Open Source Supply Chains
|
Sarah Gooding |
2026-03-26 |
757 |
--
|
|
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
|
-- |
2026-03-31 |
1,986 |
--
|
|
The Hidden Blast Radius of the Axios Compromise
|
-- |
2026-04-01 |
3,065 |
--
|
|
Node.js Drops Bug Bounty Rewards After Funding Dries Up
|
-- |
2026-04-02 |
902 |
--
|
|
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
|
-- |
2026-04-02 |
857 |
--
|
|
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
|
-- |
2026-04-03 |
1,806 |
--
|
|
North Korea’s Contagious Interview Campaign Spreads Across 5 Ecosystems, Delivering Staged RAT …
|
-- |
2026-04-07 |
2,680 |
--
|
|
Microsoft Releases Open Source Toolkit for AI Agent Runtime Security
|
-- |
2026-04-07 |
1,074 |
--
|
|
Attackers Are Impersonating a Linux Foundation Leader in Slack to Target Open …
|
-- |
2026-04-08 |
972 |
--
|
|
Feross on TBPN: How North Korea Hijacked Axios
|
-- |
2026-04-08 |
254 |
--
|
|
Don't Kill the Goose That Lays the Golden Eggs
|
Sarah Gooding |
2026-04-10 |
528 |
--
|
|
Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline, Forces Certificate Rotation
|
Sarah Gooding |
2026-04-11 |
605 |
--
|
|
108 Chrome Extensions Linked to Data Exfiltration and Session Theft via Shared …
|
Kush Pandya |
2026-04-13 |
3,881 |
--
|
|
Feross on the 10 Minutes or Less Podcast: Nobody Reads the Code
|
Sarah Gooding |
2026-04-14 |
186 |
--
|
|
Socket Selected for OpenAI's Cybersecurity Grant Program
|
Sarah Gooding |
2026-04-16 |
467 |
--
|
|
NIST Officially Stops Enriching Most CVEs as Vulnerability Volume Skyrockets
|
Sarah Gooding |
2026-04-17 |
1,465 |
--
|
|
Socket Named Top Sales Organization by RepVue
|
Sarah Gooding |
2026-04-17 |
366 |
--
|
|
Socket for Jira Is Now Available
|
Jeppe Hasseriis |
2026-04-20 |
602 |
--
|
|
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
|
Socket Research Team |
2026-04-22 |
1,195 |
--
|
|
Introducing Reports: An Extensible Reporting Framework for Socket Data
|
André Staltz |
2026-04-21 |
886 |
--
|
|
Malicious Checkmarx Artifacts Found in Official KICS Docker Repository and Code Extensions
|
Socket Research Team |
2026-04-22 |
2,911 |
--
|
|
Introducing Organization Notifications in Socket
|
Alex Morais |
2026-04-22 |
564 |
--
|
|
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
|
Socket Research Team |
2026-04-23 |
884 |
--
|
|
Introducing Data Exports
|
Ola Adekola |
2026-04-23 |
692 |
--
|
|
73 Open VSX Sleeper Extensions Linked to GlassWorm Show New Malware Activations
|
Socket Research Team |
2026-04-25 |
980 |
--
|
|
Introducing Reachability for PHP
|
Benjamin Barslev |
2026-04-24 |
1,984 |
--
|
|
Socket Has Acquired Secure Annex
|
Feross Aboukhadijeh |
2026-04-28 |
389 |
--
|
|
Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables
|
Socket Research Team |
2026-04-29 |
914 |
--
|
|
TeamPCP-Linked Supply Chain Attack Hits SAP CAP and Cloud MTA npm Packages
|
Socket Research Team |
2026-04-29 |
1,711 |
--
|
|
Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP Package Follows npm Compromise
|
Socket Research Team |
2026-04-30 |
1,340 |
--
|
|
Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets …
|
Kirill Boychenko |
2026-05-01 |
2,574 |
--
|
|
lightning PyPI Package Compromised in Supply Chain Attack
|
Socket Research Team |
2026-04-30 |
2,659 |
--
|
|
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
|
Socket Research Team |
2026-04-30 |
914 |
--
|
|
PyPI Fixes High-Severity Access Control Issues Found in Security Audit
|
Sarah Gooding |
2026-05-01 |
1,409 |
--
|
|
pnpm 11 Adds Supply Chain Protection Defaults for Minimum Release Age and …
|
Sarah Gooding |
2026-05-04 |
924 |
--
|
|
5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet …
|
Kush Pandya |
2026-05-06 |
2,840 |
--
|
|
Socket Releases Free Certified Patches for Critical vm2 Sandbox Escape
|
Wenxin Jiang and Marvin Fleischer and Jonah Ghebremichael |
2026-05-08 |
607 |
--
|
|
fsnotify Maintainer Dispute Sparks Supply Chain Concerns
|
Sarah Gooding |
2026-05-08 |
1,352 |
--
|
|
TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack
|
Socket Research Team |
2026-05-11 |
7,030 |
--
|
|
Socket Named to Rising in Cyber 2026 List of Top Cybersecurity Startups
|
Sarah Gooding |
2026-05-12 |
266 |
--
|
|
GemStuffer Campaign Abuses RubyGems as Exfiltration Channel Targeting UK Local Government
|
Joseph Edwards |
2026-05-13 |
3,825 |
--
|
|
Packagist Urges Immediate Composer Update After GitHub Actions Token Leak
|
Sarah Gooding |
2026-05-13 |
603 |
--
|
|
TeamPCP and BreachForums Launch $1,000 Contest for Supply Chain Attacks
|
Sarah Gooding |
2026-05-14 |
710 |
--
|
|
Popular node-ipc npm Package Infected with Credential Stealer
|
Socket Research Team |
2026-05-14 |
2,650 |
--
|
|
Active Supply Chain Attack Compromises @antv Packages on npm
|
Socket Research Team |
2026-05-19 |
10,666 |
--
|
|
Popular Go Decimal Library Targeted by Long-Running Typosquat with DNS Backdoor
|
Kush Pandya |
2026-05-19 |
2,564 |
--
|
|
Socket raises $60M Series C at $1B valuation led by Thrive Capital …
|
Feross Aboukhadijeh |
2026-05-20 |
1,813 |
--
|
|
Socket Raises $60M Series C at a $1B Valuation to Help Enterprises …
|
Feross Aboukhadijeh |
2026-05-20 |
551 |
--
|
|
Socket Recognized for Second Consecutive Year on Fortune Cyber 60 List
|
Sarah Gooding |
2024-10-30 |
430 |
--
|
|
Announcing SOC 2 Type 2 Compliance: Ensuring the Highest Standards of Security
|
Feross Aboukhadijeh |
2023-02-21 |
650 |
--
|
|
Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit
|
Joseph Edwards |
2026-05-20 |
7,102 |
--
|
|
npm Invalidates Granular Access Tokens as Mini Shai-Hulud Sweeps the Registry
|
Sarah Gooding |
2026-05-21 |
1,477 |
--
|
|
Laravel Lang Compromised with RCE Backdoor Across 700+ Versions
|
Socket Research Team |
2026-05-23 |
6,365 |
--
|
|
AI Has Taken Over Open Source
|
André Staltz |
2026-05-22 |
1,356 |
--
|
|
Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js …
|
Socket Research Team |
2026-05-22 |
1,356 |
--
|
|
TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of …
|
Socket Research Team |
2026-05-24 |
5,697 |
--
|
|
Feross on TBPN: Socket's Series C and the State of Software Supply …
|
Sarah Gooding |
2026-05-27 |
1,834 |
--
|
|
OSV Withdraws 157 Malware Reports After Automated False Positives Hit npm and …
|
Sarah Gooding |
2026-05-27 |
659 |
--
|
|
Malicious NuGet Package Impersonates Sicoob SDK to Exfiltrate Banking Certificates and Passwords
|
Kirill Boychenko |
2026-05-28 |
2,654 |
--
|
|
Famous Chollima Targets PHP Developers Through Compromised Packagist Package
|
Kirill Boychenko |
2026-05-31 |
1,667 |
--
|
|
Rust Moves to Restrict LLM Use in Contributions After Months of Internal …
|
Sarah Gooding |
2026-05-31 |
1,288 |
--
|
|
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages
|
Socket Research Team |
2026-06-01 |
4,194 |
--
|
|
Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD …
|
Sarah Gooding |
2026-06-03 |
2,143 |
--
|
|
pnpm 11.5 Adds Support for Recognizing npm Staged Publishes
|
Sarah Gooding |
2026-06-04 |
681 |
--
|
|
RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems
|
Sarah Gooding |
2026-06-05 |
890 |
--
|
|
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
|
Socket Research Team |
2026-06-07 |
2,293 |
--
|
|
Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via …
|
Kirill Boychenko |
2026-06-08 |
2,072 |
--
|
|
npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders
|
Sarah Gooding |
2026-06-09 |
488 |
--
|
|
Socket Partners with Replit to Block Malicious Packages in AI-Powered Development
|
Feross Aboukhadijeh |
2026-06-10 |
379 |
--
|
|
Andrew Becherer Joins Socket as Chief Information Security Officer
|
Sarah Gooding |
2026-06-11 |
485 |
--
|
|
US Government Forces Anthropic to Pull Claude Fable Days After Launch
|
Sarah Gooding |
2026-06-13 |
719 |
--
|
|
152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search …
|
Kush Pandya |
2026-06-12 |
4,624 |
--
|
|
GlassWASM: WebAssembly Malware Found in Trojanized Open VSX Extensions
|
Joseph Edwards |
2026-06-15 |
3,923 |
--
|
|
Introducing Manifest Alerts
|
André Staltz |
2026-06-16 |
602 |
--
|
|
140+ Mastra npm Packages Compromised in Coordinated Supply Chain Attack
|
Socket Research Team |
2026-06-17 |
2,970 |
--
|
|
npm Package Uses Prompt Injection and Token Flooding to Disrupt AI Malware …
|
Jean-Charles Noirot Ferrand |
2026-06-16 |
2,004 |
--
|
|
Socket Firewall Now Blocks Malicious VS Code and Open VSX Extensions
|
John Tuckner |
2026-06-17 |
705 |
--
|
|
Socket for Linear Is Now Available
|
Jeppe Hasseriis |
2026-06-15 |
586 |
--
|
|
Socket MCP Adds Org Alerts, Threat Feed Review, and Package Inspection
|
John Tuckner |
2026-06-18 |
1,150 |
--
|
|
Introducing Repository Access Permissions and Custom Roles
|
Joe Werle |
2026-06-19 |
781 |
--
|
|
GitHub Actions Checkout Now Blocks Risky pull_request_target Checkouts
|
Sarah Gooding |
2026-06-20 |
1,196 |
--
|
|
The Code You Didn't Write Is Still Yours to Defend
|
Brad Arkin |
2026-06-23 |
863 |
--
|
|
Frontier AI Is Now Critical Infrastructure
|
Sarah Gooding |
2026-06-24 |
1,631 |
--
|
|
Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to …
|
Socket Research Team |
2026-06-25 |
2,226 |
--
|
|
Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages
|
Socket Research Team |
2026-06-26 |
2,094 |
--
|
|
Rolldown Pulls Rust React Compiler Integration After Binary Size Increase
|
Sarah Gooding |
2026-06-26 |
969 |
--
|
|
Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via …
|
Kirill Boychenko |
2026-06-29 |
3,008 |
--
|
|
Risky Biz Podcast: AI Agents Are Raising the Stakes for Software Supply …
|
Sarah Gooding |
2026-06-30 |
210 |
--
|
|
PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems
|
Karlo Zanki |
2026-07-01 |
2,477 |
--
|
|
Node.js Considers Public Workflow for Security Reports Amid AI-Driven Surge
|
Sarah Gooding |
2026-07-06 |
969 |
--
|
|
pnpm 11.10 Hardens Registry Authentication to Block Token Redirection
|
Sarah Gooding |
2026-07-08 |
514 |
--
|
|
Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
|
Joseph Edwards |
2026-07-07 |
1,101 |
--
|
|
Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories
|
Kirill Boychenko |
2026-07-08 |
3,855 |
--
|
|
npm v12 Ships With Install Scripts Off by Default, Begins Deprecating 2FA-Bypass …
|
Sarah Gooding |
2026-07-08 |
988 |
--
|
|
Fake Braintree NuGet Package Skims Credit Cards and Harvests Merchant Credentials
|
Joseph Edwards |
2026-07-09 |
2,793 |
--
|
|
Compromised Injective SDK npm Package Exfiltrates Wallet Keys and Mnemonics
|
Karlo Zanki |
2026-07-09 |
1,102 |
--
|
|
jscrambler npm Package Compromised in Supply Chain Attack
|
Socket Research Team |
2026-07-11 |
1,588 |
--
|
|
Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials via Telegram
|
Kirill Boychenko |
2025-08-21 |
1,544 |
--
|
|
Manifest Confusion: How Socket Protects You
|
Socket Research Team |
2022-09-05 |
710 |
--
|
|
5 New Critical Issue Alerts
|
Bret Comnes |
2026-01-23 |
677 |
--
|
|
New Rust RFC Proposes Adding Support for Trusted Publishing ...
|
Sarah Gooding |
2024-09-12 |
628 |
--
|
|
Toptal’s GitHub Organization Hijacked: 10 Malicious Packages...
|
Kush Pandya |
2025-07-20 |
1,022 |
--
|
|
The Security Podcast in Silicon Valley: Adopting a Security ...
|
Sarah Gooding |
2024-02-09 |
597 |
--
|
|
devenv Faces Backlash Over AI-Driven Telemetry in Version 1....
|
Sarah Gooding |
2025-02-21 |
1,140 |
--
|
|
Node.js TSC Votes to Stop Distributing Corepack
|
Sarah Gooding |
2025-03-19 |
772 |
--
|
|
Massive npm Malware Campaign Leverages Ethereum Smart Contra...
|
Socket Research Team |
2024-10-31 |
966 |
--
|
|
PyPI Introduces Digital Attestations to Strengthen Python Pa...
|
Sarah Gooding |
2024-11-15 |
935 |
--
|
|
The Landscape of Malicious Open Source Packages: 2025 Mid‑Ye...
|
Socket Research Team |
2025-05-14 |
1,175 |
--
|
|
Introducing Rust Support in Socket
|
Trevor Norris |
2025-07-31 |
729 |
--
|
|
Understanding the Security Concerns of npm Shrinkwrap - Sock...
|
Sarah Gooding |
2024-08-09 |
1,190 |
--
|
|
Nx Investigation Reveals GitHub Actions Workflow Exploit Led...
|
Sarah Gooding |
2025-08-26 |
1,183 |
--
|
|
Introducing Scala and Kotlin Support in Socket
|
Joe Werle |
2026-01-23 |
680 |
--
|
|
TON Wallet Security Threat: Malicious npm Package Steals Cry...
|
Socket Research Team |
2025-02-24 |
883 |
--
|
|
Cyber Insurance Premiums Expected to Increase in 2024, Ranso...
|
Sarah Gooding |
2024-01-19 |
721 |
--
|
|
Socket Now Protects the Chrome Extension Ecosystem
|
Joe Werle |
2025-07-30 |
683 |
--
|
|
Introducing Dashboard Analytics
|
Charlie Gerard |
2024-09-05 |
519 |
--
|
|
Crates.io Implements Trusted Publishing Support
|
Sarah Gooding |
2025-07-16 |
663 |
--
|
|
New Proposed CISA Mandate Would Require Critical Infrastruct...
|
Sarah Gooding |
2024-04-04 |
733 |
--
|
|
Malicious Koishi Chatbot Plugin Exfiltrates Messages Trigger...
|
Kirill Boychenko |
2025-05-19 |
757 |
--
|
|
The Growing Risk of Malicious Browser Extensions
|
Kush Pandya |
2025-06-13 |
1,110 |
--
|
|
Socket Introduces New Dashboard Threat Feed
|
Alex Morais |
2024-02-15 |
415 |
--
|
|
The Pair Program Podcast: Feross Aboukhadijeh on Preserving ...
|
Sarah Gooding |
2025-03-10 |
481 |
--
|
|
Introducing Socket
|
Feross Aboukhadijeh |
2022-03-01 |
1,159 |
--
|
|
Malicious Ruby Gems Exfiltrate Telegram Tokens and Messages ...
|
Kirill Boychenko |
2025-05-21 |
1,025 |
--
|
|
CISA Brings KEV Data to GitHub
|
Sarah Gooding |
2025-01-29 |
633 |
--
|
|
Risky Biz Podcast: Using LLMs for Analysis and Explanation i...
|
Feross Aboukhadijeh |
2023-10-25 |
456 |
--
|
|
Why Vulnerability Scanning Isn't Enough To Protect Your App ...
|
Feross Aboukhadijeh |
2024-12-17 |
821 |
--
|
|
How Socket Protects Against Revival Hijacking Attacks on PyP...
|
Sarah Gooding |
2024-09-06 |
729 |
--
|
|
Introducing Python Support
|
Feross Aboukhadijeh |
2023-03-01 |
1,118 |
--
|
|
PyPI on Ultralytics Supply Chain Attack: Poor CI/CD Practice...
|
Sarah Gooding |
2024-12-13 |
825 |
--
|
|
Malicious PyPI Package Targets Discord Developers with Remot...
|
Socket Research Team |
2022-03-21 |
913 |
--
|
|
Go Supply Chain Attack: Malicious Package Exploits Go Module...
|
Kirill Boychenko |
2025-02-04 |
1,167 |
--
|
|
npm Phishing Email Targets Developers with Typosquatted Doma...
|
Sarah Gooding |
2025-07-18 |
652 |
--
|
|
Introducing Socket Dependency Overview
|
Bret Comnes |
2023-03-24 |
1,026 |
--
|
|
U.S. Government Budget Proposal Seeks Major Increase to Cybe...
|
Sarah Gooding |
2024-03-14 |
849 |
--
|
|
DuckDB npm Account Compromised in Continuing Supply Chain At...
|
Socket Research Team |
2025-09-09 |
331 |
--
|
|
Malicious ‘Checker’ Packages on PyPI Probe TikTok and Instag...
|
Olivia Brown |
2023-04-29 |
1,251 |
--
|
|
Introducing Socket Fix for Safe, Automated Dependency Upgrad...
|
John-David Dalton |
2025-04-25 |
575 |
--
|
|
What Is SCA with Reachability Analysis?
|
Martin Torp |
2024-01-23 |
659 |
--
|
|
The Bad Seeds: Malicious npm and PyPI Packages Pose as Devel...
|
Kirill Boychenko |
2025-04-22 |
1,180 |
--
|
|
tea.xyz Spam Plagues npm and RubyGems Package Registries - S...
|
Sarah Gooding |
2024-04-27 |
650 |
--
|
|
Using GPT at Work
|
Mikola Lysenko |
2023-01-24 |
1,055 |
--
|
|
Lazarus Expands Malicious npm Campaign: 11 New Packages Add ...
|
Kirill Boychenko |
2025-03-11 |
1,054 |
--
|
|
Data Theft Repackaged: A Case Study in Malicious Wrapper Pac...
|
Kush Pandya |
2024-12-11 |
924 |
--
|
|
PodRocket Podcast: Inside the Recent npm Supply Chain Attack...
|
Sarah Gooding |
2025-10-02 |
235 |
--
|
|
Obfuscation 101: Unmasking the Tricks Behind Malicious Code ...
|
Kush Pandya |
2025-03-28 |
768 |
--
|
|
Next.js Patches Critical Middleware Vulnerability (CVE-2025-...
|
Sarah Gooding |
2025-03-24 |
642 |
--
|
|
Tick Tock, Your Credentials Are Gone: The Maven Package With...
|
Kush Pandya |
2024-01-25 |
1,083 |
--
|
|
Oracle Drags Its Feet in the JavaScript Trademark Dispute - ...
|
Sarah Gooding |
2025-02-07 |
725 |
--
|
|
How to Protect Your Projects from the Risks of Deprecated np...
|
Sarah Gooding |
2024-01-25 |
908 |
--
|
|
White House Cybersecurity Advisor Calls for Ban on Using Ins...
|
Sarah Gooding |
2024-10-08 |
725 |
--
|
|
node-ip Maintainer Restores GitHub Repo After Archiving Due ...
|
Sarah Gooding |
2024-07-10 |
928 |
--
|
|
NVD Halts CVE Enrichment
|
Sarah Gooding |
2024-02-13 |
679 |
--
|
|
Meet Socket at Black Hat and DEF CON 2025 in Las Vegas …
|
Sarah Gooding |
2025-07-12 |
633 |
--
|
|
The Coana Approach to Reachability Analysis
|
Martin Torp |
2024-08-09 |
1,104 |
--
|
|
Malicious npm Package Masquerades as Noblox.js, Targeting Ro...
|
Socket Research Team |
2024-02-06 |
877 |
--
|
|
Socket VSCode Extension
|
Bradley Meck Farias |
2026-01-23 |
468 |
--
|
|
AGENTS.md Gains Traction as an Open Format for AI Coding Age...
|
Sarah Gooding |
2025-09-03 |
899 |
--
|
|
Threat Actor Exposes Playbook for Exploiting npm to Build Bl...
|
Kirill Boychenko |
2024-10-31 |
1,165 |
--
|
|
MCP Steering Committee Launches Official MCP Registry in Pre...
|
Sarah Gooding |
2025-09-09 |
628 |
--
|
|
Inside the Business of Ransomware: Insights from Reddit AMA ...
|
Sarah Gooding |
2024-12-17 |
1,215 |
--
|
|
These Chinese devs are storing 1000s of eBooks on GitHub and...
|
Ax Sharma |
2022-11-02 |
654 |
--
|
|
Ransomware in 2024: Record-Low Payment Rate Signals Changing...
|
Sarah Gooding |
2025-02-14 |
942 |
--
|
|
Risky Business Podcast: How Socket Combats Malware in Open S...
|
Sarah Gooding |
2024-02-15 |
416 |
--
|
|
A Short History of Protestware
|
Sarah Gooding |
2024-01-13 |
1,236 |
--
|
|
Malicious npm Package Targets Solana Developers and Hijacks ...
|
Socket Research Team |
2026-03-10 |
730 |
--
|
|
TypeScript Native Previews: 10x Faster Compiler Now on npm f...
|
Sarah Gooding |
2025-05-23 |
592 |
--
|
|
Free Software Foundation Goes to Bat for AGPL in Amicus Brie...
|
Sarah Gooding |
2025-03-06 |
775 |
--
|
|
3.7 Million Fake GitHub Stars: A Growing Threat Linked to Sc...
|
Hao He |
2024-08-27 |
1,309 |
--
|
|
Rspack Introduces Rslint, a TypeScript-First Linter Written ...
|
Sarah Gooding |
2025-08-20 |
757 |
--
|
|
Tines Integration Generates Real-Time Critical Vulnerability...
|
Sarah Gooding |
2024-01-26 |
384 |
--
|
|
Introducing the Socket Python SDK
|
Douglas Coburn |
2024-09-13 |
403 |
--
|
|
Spam-tastic! npm Registry Swamped by Bizarre John Wick Frenz...
|
Bradley Meck Farias |
2026-03-22 |
394 |
--
|
|
New Report Warns of LLM-Enhanced Cyber Threats: Polymorphic ...
|
Sarah Gooding |
2024-05-29 |
881 |
--
|
|
vlt Debuts New JavaScript Package Manager and Serverless Reg...
|
Sarah Gooding |
2024-11-08 |
687 |
--
|
|
Signing is Just the Start
|
Mikola Lysenko |
2023-05-04 |
538 |
--
|
|
Nominating Bradley Meck Farias for OpenSSF Governing Board -...
|
Feross Aboukhadijeh |
2023-02-14 |
323 |
--
|
|
Socket Introduces Free Team Plan Upgrades for Open Source Pr...
|
Sarah Gooding |
2024-03-12 |
428 |
--
|
|
Survey Finds Over Half of CISOs Manage 10+ Security Areas wi...
|
Sarah Gooding |
2025-06-18 |
756 |
--
|
|
2023 Ransomware Trends: Rising Ransom Payments Drive Higher ...
|
Sarah Gooding |
2023-12-08 |
1,204 |
--
|
|
Critical Vulnerability in Popular npm form-data Package Used...
|
Sarah Gooding |
2025-07-22 |
507 |
--
|
|
Active Supply Chain Attack: npm Phishing Campaign Leads to P...
|
Sarah Gooding |
2025-07-19 |
566 |
--
|
|
Malicious npm Package Disguised as Advcash Integration Trigg...
|
Socket Research Team |
2025-04-14 |
937 |
--
|
|
Feross on Risky Business Weekly Podcast: npm’s Ongoing Suppl...
|
Sarah Gooding |
2025-09-10 |
300 |
--
|
|
Open Source CAI Framework Handles Pen Testing Tasks up to 3,...
|
Sarah Gooding |
2025-07-09 |
1,058 |
--
|
|
NVD Concedes Inability to Keep Pace with Surging CVE Disclos...
|
Sarah Gooding |
2025-03-28 |
986 |
--
|
|
Updating a package every day would take 30 years to catch bi...
|
Bradley Meck Farias |
2023-01-18 |
680 |
--
|
|
The AI Advantage: Reshaping Cybersecurity in the Age of Autonomous Threats
|
Sarah Gooding |
2024-04-25 |
997 |
--
|
|
VulnCon 2025: NVD Scraps Industry Consortium Plan, Raising Q...
|
Sarah Gooding |
2025-04-10 |
688 |
--
|
|
11 Malicious Go Packages Distribute Obfuscated Remote Payloa...
|
Olivia Brown |
2025-08-06 |
1,094 |
--
|
|
Introducing "safe npm", a Socket npm Wrapper
|
Bradley Meck Farias |
2023-03-16 |
1,275 |
--
|
|
Socket Named Among Top Cybersecurity Companies in Fortune’s ...
|
Sarah Gooding |
2023-12-13 |
363 |
--
|
|
How to Use Socket to Find out if You Were Affected by …
|
Socket Research Team |
2024-03-30 |
754 |
--
|
|
Introducing pnpm support in Socket
|
Mikola Lysenko |
2023-03-14 |
296 |
--
|
|
JavaScript Community Launches e18e Initiative to Improve Eco...
|
Sarah Gooding |
2024-07-01 |
548 |
--
|
|
Updated and Ongoing Supply Chain Attack Targets CrowdStrike ...
|
Sarah Gooding |
2025-09-16 |
884 |
--
|
|
Introducing License Overlays: Smarter License Management for...
|
Christopher Bailey |
2025-08-01 |
771 |
--
|
|
Introducing the New Socket Project Health Reports: Smarter, ...
|
Joe Werle |
2023-11-07 |
577 |
--
|
|
require(esm) Backported to Node.js 20, Paving the Way for ES...
|
Sarah Gooding |
2024-12-05 |
661 |
--
|
|
Outgoing Biden Administration Issues Sweeping Executive Orde...
|
Sarah Gooding |
2025-01-16 |
852 |
--
|
|
Knip Hits 500 Releases with v5.62.0, Improving TypeScript Co...
|
Sarah Gooding |
2026-02-24 |
375 |
--
|
|
TypeScript is Porting Its Compiler to Go for 10x Faster Buil...
|
Sarah Gooding |
2025-03-11 |
1,083 |
--
|
|
Malicious PyPI Package Targets WooCommerce Stores with Autom...
|
Socket Research Team |
2025-04-02 |
1,196 |
--
|
|
Announcing Socket for GitHub 1.0
|
Feross Aboukhadijeh |
2022-06-15 |
962 |
--
|
|
Django Joins curl in Pushing Back on AI Slop Security Report...
|
Sarah Gooding |
2025-06-30 |
787 |
--
|
|
Combatting Alert Fatigue by Prioritizing Malicious Intent - ...
|
Feross Aboukhadijeh |
2024-09-23 |
1,228 |
--
|
|
White House to Tackle Cybersecurity Regulation Fragmentation...
|
Sarah Gooding |
2026-02-26 |
916 |
--
|
|
OpenJS: “XZ Utils Cyberattack Likely Not an Isolated Inciden...
|
Sarah Gooding |
2024-04-17 |
637 |
--
|
|
Developer Accuses Tencent of Copyright Violation After Pytho...
|
Sarah Gooding |
2026-03-12 |
1,204 |
--
|
|
Introducing Bot Commands
|
Bret Comnes |
2022-08-26 |
651 |
--
|
|
Orbit Chain Terminates Negotiations, Offers $8M Bounty for I...
|
Sarah Gooding |
2024-01-02 |
772 |
--
|
|
Deno 2.4 Brings Back deno bundle, Improves Dependency Manage...
|
Sarah Gooding |
2025-07-08 |
679 |
--
|
|
Potemkin Understanding in LLMs: New Study Reveals Flaws in ...
|
Sarah Gooding |
2025-07-01 |
1,186 |
--
|
|
Internet Archive Hacked, 31 Million Record Compromised
|
Sarah Gooding |
2024-09-28 |
450 |
--
|
|
Gem Cooperative Emerges as a Community-Run Alternative to Ru...
|
Sarah Gooding |
2025-10-05 |
871 |
--
|
|
Popular Tinycolor npm Package Compromised in Supply Chain At...
|
Socket Research Team |
2025-09-15 |
721 |
--
|
|
Chinchilla Squeaks Podcast: Modern Solutions for Securing So...
|
Sarah Gooding |
2026-03-03 |
1,476 |
--
|
|
Python Adopts Standard Lock File Format for Reproducible Ins...
|
Sarah Gooding |
2025-03-31 |
678 |
--
|
|
“Valkey” Open Source Redis Fork Backed by Linux Foundation, ...
|
Sarah Gooding |
2024-03-29 |
610 |
--
|
|
DevTools Podcast: Rethinking Open Source Security Beyond Buz...
|
Sarah Gooding |
2024-01-17 |
354 |
--
|
|
Risky Biz Podcast: How Socket Goes Beyond Vulnerabilities to...
|
Sarah Gooding |
2024-07-22 |
284 |
--
|
|
Let's make JS RegExps Streamy
|
Bradley Meck Farias |
2023-02-17 |
504 |
--
|
|
Improved Support for npm and Yarn in Socket
|
Feross Aboukhadijeh |
2023-02-02 |
438 |
--
|
|
Major Open Source Foundations Form Initiative Aimed at Build...
|
Sarah Gooding |
2024-04-04 |
746 |
--
|
|
PyPI Now Supports iOS and Android Wheels for Mobile Python D...
|
Sarah Gooding |
2025-02-12 |
660 |
--
|
|
Deno Standard Library Stabilized After 4 Years and 4,000 Com...
|
Sarah Gooding |
2026-03-10 |
620 |
--
|
|
LockBit Resurfaces with Attack on Pharmaceutical Company, Le...
|
Sarah Gooding |
2024-03-21 |
810 |
--
|
|
Typosquatted Go Packages Deliver Malware Loader Targeting Li...
|
Kirill Boychenko |
2025-03-04 |
989 |
--
|
|
Cyber Insurance Market Projected to Reach $43 Billion by 203...
|
Sarah Gooding |
2024-07-04 |
765 |
--
|
|
Bun 1.2.19 Adds Isolated Installs for Better Monorepo Suppor...
|
Sarah Gooding |
2025-07-22 |
509 |
--
|
|
Dutch National Police Disrupt Redline and Meta Malware Opera...
|
Sarah Gooding |
2024-10-29 |
486 |
--
|
|
uv: Python's New High-Speed Package Manager Promises to Simp...
|
Sarah Gooding |
2026-04-07 |
1,128 |
--
|
|
Tracking Protestware Spread: 28 npm Packages Affected by Pay...
|
Olivia Brown |
2025-07-15 |
787 |
--
|
|
Unverified npm Account Takeover Vulnerability For Sale on Da...
|
Sarah Gooding |
2024-07-06 |
1,063 |
--
|
|
What’s in your npm stat counter? A love doll store—we hope n...
|
Ax Sharma |
2026-02-23 |
470 |
--
|
|
CISA Kills Off RSS Feeds for KEVs and Cyber Alerts
|
Sarah Gooding |
2025-05-12 |
784 |
--
|
|
Introducing Java Support in Socket
|
Eli Insua |
2024-10-15 |
1,082 |
--
|
|
Go Support Is Now Generally Available
|
Joe Werle |
2025-04-17 |
449 |
--
|
|
pnpm 10.12 Introduces Global Virtual Store and Expanded Vers...
|
Sarah Gooding |
2025-06-11 |
583 |
--
|
|
OpenSSF Warns of Reputation Farming Leveraging Closed GitHub...
|
Sarah Gooding |
2024-06-26 |
502 |
--
|
|
Announcing the Socket Web Extension
|
Arjun Barrett |
2023-07-31 |
503 |
--
|
|
Turtles, Clams, and Cyber Threat Actors: Shell Usage - Socke...
|
Kirill Boychenko |
2025-04-11 |
1,097 |
--
|
|
OpenJS Launches New Collaboration to Improve Interoperabilit...
|
Sarah Gooding |
2024-02-27 |
1,114 |
--
|
|
RubyGems.org Adds New Maintainer Role
|
Sarah Gooding |
2024-11-12 |
538 |
--
|
|
Recent Trends in Malicious Packages Targeting Discord - Sock...
|
Socket Research Team |
2026-03-10 |
734 |
--
|
|
Judicious JSON
|
Bradley Meck Farias |
2023-12-26 |
951 |
--
|
|
Researcher Exposes Zero-Day Clickjacking Vulnerabilities in ...
|
Jonathan Leitschuh |
2025-08-19 |
1,184 |
--
|
|
Introducing Enhanced Alert Actions and Triage Functionality ...
|
Joe Werle |
2024-06-27 |
811 |
--
|
|
Node.js Doubles Security Releases with Newly Automated Process, Re-Evaluates Unsupported Experimental Features
|
Sarah Gooding |
2024-08-17 |
586 |
--
|
|
Unveiling the Dangers of the "AnyDesk-Malcom" Malicious Python Package
|
Socket Research Team |
2023-08-23 |
551 |
--
|
|
Python Overtakes JavaScript as Top Programming Language on G...
|
Sarah Gooding |
2024-10-30 |
755 |
--
|
|
Socket Acquires Coana to Bring Best-in-Class Reachability An...
|
Feross Aboukhadijeh |
2025-04-23 |
539 |
--
|
|
Bun 1.2 Released with Improved Node.js Compatibility and Bui...
|
Sarah Gooding |
2025-01-22 |
772 |
--
|
|
Customize your GitHub Issue Alerts
|
Bret Comnes |
2026-01-23 |
531 |
--
|
|
pnpm 9.5 Introduces Catalogs: Shareable Dependency Version S...
|
Sarah Gooding |
2024-07-08 |
694 |
--
|
|
Announcing New Default Security Policies
|
Philipp Burckhardt |
2024-08-28 |
1,326 |
--
|
|
How to Evaluate an SCA with Reachability: Benchmarking Hard-...
|
Martin Torp |
2024-11-05 |
1,190 |
--
|
|
Gmail For Exfiltration: Malicious npm Packages Target Solana...
|
Kirill Boychenko |
2026-03-20 |
928 |
--
|
|
Michigan TypeScript Founder Successfully Runs Doom Inside Ty...
|
Sarah Gooding |
2026-03-24 |
879 |
--
|
|
New CVE Forecasting Tool Predicts 47,000 Disclosures in 2025...
|
Sarah Gooding |
2025-07-07 |
488 |
--
|
|
The Benefit of Doing Reachability Analysis
|
Anders Søndergaard |
2024-03-08 |
564 |
--
|
|
PyPI’s New Archival Feature Closes a Major Security Gap - So...
|
Sarah Gooding |
2025-01-30 |
743 |
--
|
|
AI + a16z Podcast: Vibe Coding, Security Risks, and the Path...
|
Sarah Gooding |
2025-07-25 |
182 |
--
|
|
Unpacking the ROI of Coana's SCA With Reachability Analysis ...
|
Anders Søndergaard |
2024-05-15 |
462 |
--
|
|
Python Software Foundation Announces 5-Year Sponsorship Comm...
|
Sarah Gooding |
2024-01-01 |
601 |
--
|
|
Malicious npm Packages Inject SSH Backdoors via Typosquatted...
|
Kirill Boychenko |
2024-11-22 |
1,092 |
--
|
|
How to Integrate Socket Into Your Bitbucket Pipeline - Socke...
|
Douglas Coburn |
2023-12-12 |
414 |
--
|
|
Node.js Community Debate Intensifies Over Enabling Corepack ...
|
Sarah Gooding |
2024-02-08 |
1,299 |
--
|
|
OpenJS Foundation Is Now a CNA for 40+ JavaScript Projects U...
|
Sarah Gooding |
2025-05-28 |
655 |
--
|
|
JSR: What We Know So Far About Deno’s New JavaScript Package...
|
Sarah Gooding |
2024-02-22 |
1,193 |
--
|
|
Cleaning up import paths in JS/TS packages
|
Bradley Meck Farias |
2023-05-04 |
583 |
--
|
|
Socket at Black Hat and DEF CON 2023
|
Amjed Aboukhadijeh |
2025-05-12 |
176 |
--
|
|
Risky Biz Podcast: Making Reachability Analysis Work in Real...
|
Sarah Gooding |
2025-08-28 |
330 |
--
|
|
Announcing SOC 2 Type 1 Compliance
|
Feross Aboukhadijeh |
2022-12-07 |
652 |
--
|
|
TC39 Advances Array.fromAsync, Error.isError, and Explicit R...
|
Sarah Gooding |
2025-06-02 |
438 |
--
|
|
Socket Partners with CISA to Champion 'Secure by Design' Sta...
|
Sarah Gooding |
2024-05-08 |
456 |
--
|
|
libxml2 Maintainer Ends Embargoed Vulnerability Reports, Cit...
|
Sarah Gooding |
2025-06-17 |
1,015 |
--
|
|
TC39 Advances 10+ ECMAScript Proposals: Key Features to Watc...
|
Sarah Gooding |
2024-10-09 |
1,115 |
--
|
|
ALPHV/BlackCat Fakes Law Enforcement Takedown to Scam Affili...
|
Sarah Gooding |
2024-03-06 |
720 |
--
|
|
AI + a16z Podcast: Combatting Modern Supply Chain Attacks wi...
|
Sarah Gooding |
2026-02-24 |
311 |
--
|
|
TC39 Advances 3 Proposals to Stage 4: RegExp Escaping, Float...
|
Sarah Gooding |
2025-02-20 |
839 |
--
|
|
MCP Community Begins Work on Official MCP Metaregistry - Soc...
|
Sarah Gooding |
2025-05-09 |
900 |
--
|
|
CISA Rebuffs Funding Concerns as CVE Foundation Draws Critic...
|
Sarah Gooding |
2025-04-24 |
1,133 |
--
|
|
GitHub Removes Malicious Pull Requests Targeting Open Source...
|
Sarah Gooding |
2026-02-26 |
512 |
--
|
|
Supply Chain Attack on Rspack npm Packages Injects Cryptojac...
|
Socket Research Team |
2024-12-19 |
777 |
--
|
|
How Threat Actors are Abusing GitHub’s File Upload Feature t...
|
Sarah Gooding |
2024-04-23 |
921 |
--
|
|
Why Your SCA Tool Sucks
|
Feross Aboukhadijeh |
2023-06-26 |
603 |
--
|
|
Follow-up and Clarification on Recent Malicious Ruby Gems Ca...
|
Sarah Gooding |
2025-08-07 |
381 |
--
|
|
TC39 Advances 11 Proposals for Math Precision, Binary APIs, ...
|
Sarah Gooding |
2025-08-06 |
664 |
--
|
|
8 More Malicious Firefox Extensions: Exploiting Popular Game Recognition, Hijacking User Sessions, …
|
Kush Pandya |
2025-07-04 |
1,112 |
--
|
|
Announcing Socket Project Health Reports
|
Feross Aboukhadijeh |
2023-04-04 |
557 |
--
|
|
Node.js Delivers First LTS with require(esm) Enabled, Enhanc...
|
Sarah Gooding |
2024-12-06 |
584 |
--
|
|
Fidelity National Financial Cyberattack Spotlights a Surge i...
|
Sarah Gooding |
2023-11-26 |
1,153 |
--
|
|
Biome Announces v2.0 Beta with Plugin System and Type Inform...
|
Sarah Gooding |
2025-03-25 |
795 |
--
|
|
Nx npm Packages Compromised in Supply Chain Attack Weaponizi...
|
Socket Research Team |
2025-08-26 |
1,129 |
--
|
|
Opengrep Adds Apex Support and New Rule Controls in Latest Updates
|
Sarah Gooding |
2025-08-12 |
622 |
--
|
|
Malicious npm Campaign Targets Ethereum Developers with Fake...
|
Socket Research Team |
2025-01-02 |
773 |
--
|
|
Introducing Pull Request Stories to Help Security Teams Tra...
|
André Staltz |
2025-09-08 |
576 |
--
|
|
Weaponizing OAST: How Malicious Packages Exploit npm, PyPI, ...
|
Kirill Boychenko |
2025-01-03 |
980 |
--
|
|
Why Socket Joined the Open Source Security Foundation - Sock...
|
Feross Aboukhadijeh |
2022-12-05 |
394 |
--
|
|
What’s New at Socket: Introducing Our Product Changelog - So...
|
Sarah Gooding |
2024-07-25 |
290 |
--
|
|
NIST Drafts New Security Framework to Tackle Emerging Risks ...
|
Sarah Gooding |
2024-06-02 |
738 |
--
|
|
Highlights from the 2024 Rails Community Survey
|
Sarah Gooding |
2024-09-25 |
974 |
--
|
|
Subscribe to the Socket Blog
|
Bret Comnes |
2023-05-03 |
128 |
--
|
|
The Alarming NVD Backlog: Over 50% of Known Exploited Vulner...
|
Sarah Gooding |
2024-02-12 |
758 |
--
|
|
New tea.xyz Crypto Spam Targets Open Source Projects on GitH...
|
Sarah Gooding |
2024-02-21 |
1,157 |
--
|
|
Surveillance Malware Hidden in npm and PyPI Packages Targets Developers with Keyloggers, …
|
Socket Research Team |
2025-07-23 |
1,134 |
--
|
|
Python Software Foundation Expands CNA Scope to Include Pall...
|
Sarah Gooding |
2024-09-09 |
552 |
--
|
|
Socket for VSCode now supports Python
|
Arjun Barrett |
2023-06-22 |
240 |
--
|
|
Rubygems Ecosystem Support Now Generally Available
|
Eli Insua |
2025-04-15 |
385 |
--
|
|
New Website “Is It Really FOSS?” Tracks Transparency in Open...
|
Sarah Gooding |
2025-08-15 |
971 |
--
|
|
Creating an Effective Vulnerability Management Program for O...
|
Martin Torp |
2024-12-17 |
1,144 |
--
|
|
AI Slop Is Polluting Bug Bounty Platforms with Fake Vulnerab...
|
Sarah Gooding |
2025-05-06 |
964 |
--
|
|
Redesigned Repositories Page: A Faster Way to Prioritize Sec...
|
Sarah Gooding |
2025-04-09 |
434 |
--
|
|
pnpm 10.16 Adds New Setting for Delayed Dependency Updates -...
|
Sarah Gooding |
2025-09-15 |
807 |
--
|
|
Supply Chain Attack on LottieFiles Player Caused by Compromi...
|
Sarah Gooding |
2024-10-31 |
583 |
--
|
|
NVD Quietly Sweeps 100K+ CVEs Into a “Deferred” Black Hole -...
|
Sarah Gooding |
2025-04-04 |
912 |
--
|
|
Two Typosquatting Python Packages Exploit Discord CDN to Dep...
|
Socket Research Team |
2024-02-16 |
763 |
--
|
|
Stay Ahead of npm Malware: Introducing Socket's Real-Time Th...
|
Charlie Gerard |
2023-12-15 |
276 |
--
|
|
Introducing Tier 1 Reachability: Precision CVE Triage for En...
|
Martin Torp |
2025-09-09 |
841 |
--
|
|
Packaging Trends in Python: Highlights from the 2023 Develop...
|
Sarah Gooding |
2024-08-30 |
891 |
--
|
|
Enhancing Open-Source Compliance: Introducing Socket’s Advan...
|
Christopher Bailey |
2024-10-17 |
1,227 |
--
|
|
Malicious Python Package Typosquats Popular passlib Library,...
|
Kush Pandya |
2025-06-24 |
831 |
--
|
|
The Push to Ban Ransom Payments Is Gaining Momentum
|
Sarah Gooding |
2024-05-22 |
1,097 |
--
|
|
New Report Highlights Surge in 2024 Ransomware Activity from...
|
Sarah Gooding |
2024-07-17 |
898 |
--
|
|
Introducing Dependency Divergence GitHub Action
|
Bradley Meck Farias |
2023-10-25 |
1,108 |
--
|
|
Static vs. Runtime Reachability: Insights from Latio’s On th...
|
Sarah Gooding |
2026-02-26 |
411 |
--
|
|
Limitations of CVE-Based Security Scanners: A Deep Dive into...
|
Feross Aboukhadijeh |
2023-07-05 |
734 |
--
|
|
Introducing Socket's New License Features
|
Christopher Bailey |
2024-07-22 |
1,036 |
--
|
|
Node.js TSC Declines to Endorse Feature Bounty Program - Soc...
|
Sarah Gooding |
2025-05-07 |
950 |
--
|
|
SEC Cracks Down on Unreported Data Breaches with New 30-Day ...
|
Sarah Gooding |
2024-05-21 |
796 |
--
|
|
Socket Security Scan - August 10
|
Socket Research Team |
2023-08-10 |
464 |
--
|
|
New Python Packaging Proposal Aims to Solve Phantom Dependen...
|
Sarah Gooding |
2025-01-07 |
704 |
--
|
|
North Korean APT Lazarus Targets Developers with Malicious n...
|
Socket Research Team |
2025-01-29 |
1,066 |
--
|
|
Cloudflare Workers Expands npm Package Support by Combining ...
|
Sarah Gooding |
2024-09-11 |
558 |
--
|
|
How Socket Combats Insidious Typosquatting Supply Chain Atta...
|
Sarah Gooding |
2023-11-24 |
694 |
--
|
|
Ledger Connect-Kit Supply Chain Attack Hits Decentralized C...
|
Sarah Gooding |
2023-12-14 |
695 |
--
|
|
Supply Chain Attacks Targeting LLM Application Developers: T...
|
Socket Research Team |
2024-10-24 |
1,168 |
--
|
|
LDAPjs Open Source Project Decommissioned After Maintainer R...
|
Sarah Gooding |
2024-05-16 |
902 |
--
|
|
Python 3.14 Released With Template String Literals, Deferred...
|
Sarah Gooding |
2025-10-07 |
592 |
--
|
|
npm Adopts OIDC for Trusted Publishing in CI/CD Workflows - ...
|
Sarah Gooding |
2025-08-08 |
759 |
--
|
|
ESLint Approves RFC to Add Support for TypeScript Config Fil...
|
Sarah Gooding |
2024-05-25 |
642 |
--
|
|
Malicious npm Packages Impersonate Flashbots SDKs, Targeting...
|
Kush Pandya |
2025-09-05 |
1,069 |
--
|
|
npm ‘is’ Package Hijacked in Expanding Supply Chain Attack -...
|
Socket Research Team |
2025-07-22 |
904 |
--
|
|
Safari 18.4 Ships 3 New JavaScript Features from the TC39 Pi...
|
Sarah Gooding |
2026-03-20 |
601 |
--
|
|
The Rise of Slopsquatting: How AI Hallucinations Are Fueling...
|
Sarah Gooding |
2025-04-08 |
1,211 |
--
|
|
Cloudflare Adds Security.txt Setup Wizard
|
Sarah Gooding |
2024-09-30 |
517 |
--
|
|
Nightmares on npm: How Two Malicious Packages Facilitate Dat...
|
Kush Pandya |
2024-10-09 |
751 |
--
|
|
Vulnerability Scanning is Broken
|
Martin Torp |
2024-02-11 |
709 |
--
|
|
Node Congress Speaker Showcase: Interview with Feross Aboukhadijeh
|
Sarah Gooding |
2024-06-13 |
242 |
--
|
|
Introducing Historical Analytics – Now in Beta
|
Phil Gates-Idem |
2025-04-24 |
504 |
--
|
|
NIST Under Federal Audit for NVD Processing Backlog and Dela...
|
Sarah Gooding |
2025-05-20 |
669 |
--
|
|
LockBit Takedown: U.S. Sanctions Ransomware Affiliates, Inte...
|
Sarah Gooding |
2024-02-20 |
528 |
--
|
|
Announcing Precomputed Reachability Analysis in Socket - Soc...
|
Martin Torp |
2025-07-30 |
870 |
--
|
|
Enhanced Security Scanning with Improved AI Alert Defaults -...
|
Philipp Burckhardt |
2024-03-25 |
501 |
--
|
|
Malicious npm Packages Use Telegram to Exfiltrate BullX Cred...
|
Kush Pandya |
2025-05-08 |
772 |
--
|
|
Socket Joins Forces with Ecosystems to Strengthen Open Sourc...
|
Feross Aboukhadijeh |
2023-03-15 |
447 |
--
|
|
How to Use Socket in Your GitLab Pipeline for Enhanced Secur...
|
Douglas Coburn |
2023-11-22 |
481 |
--
|
|
The “Non-Existent Author” Alert: How to Safeguard Against th...
|
Sarah Gooding |
2026-02-24 |
672 |
--
|
|
Namecheap Takes Down Polyfill.io Service Following Supply Ch...
|
Sarah Gooding |
2024-02-24 |
1,024 |
--
|
|
Pull Request Alerts in Slack
|
Bret Comnes |
2026-01-23 |
82 |
--
|
|
Node.js TSC Confirms: No Intention to Remove npm from Distri...
|
Sarah Gooding |
2024-01-24 |
1,019 |
--
|
|
Mobile, Alabama Hospital Refuses to Pay Settlement in Landma...
|
Sarah Gooding |
2026-02-24 |
706 |
--
|
|
Malicious npm Package Exploits WhatsApp Authentication with ...
|
Kush Pandya |
2024-11-15 |
916 |
--
|
|
Introducing SSO
|
Alex Morais |
2024-04-29 |
296 |
--
|
|
Malicious npm Packages Target React, Vue, and Vite Ecosystem...
|
Kush Pandya |
2025-05-21 |
1,083 |
--
|
|
CISA Launches Vulnrichment Project as NVD Backlog Hits 10,00...
|
Sarah Gooding |
2024-05-09 |
965 |
--
|
|
Node.js Homepage Adds Paid Support Link, Prompting Contributor Pushback
|
Sarah Gooding |
2025-06-25 |
1,325 |
--
|
|
CyberBytes Podcast: Open Source Security Shifts Towards Tackling Supply Chain Threats
|
Sarah Gooding |
2024-02-06 |
293 |
--
|
|
The Risks of Misguided Research in Supply Chain Security - S...
|
Sarah Gooding |
2025-01-08 |
1,059 |
--
|
|
Another Wave: North Korean Contagious Interview Campaign Dro...
|
Kirill Boychenko |
2025-06-25 |
1,123 |
--
|
|
Supply Chain Attack Detected in Solana's web3.js Library - S...
|
Sarah Gooding |
2024-12-02 |
711 |
--
|
|
PyPI Slashes Malware Response Time: 90% of Issues Resolved i...
|
Sarah Gooding |
2024-08-21 |
1,087 |
--
|
|
PEP 810 Proposes Explicit Lazy Imports for Python 3.15 - Soc...
|
Sarah Gooding |
2025-10-02 |
811 |
--
|
|
60 Malicious npm Packages Leak Network and Host Data in Acti...
|
Kirill Boychenko |
2025-05-23 |
885 |
--
|
|
Noxia: Emerging Dark Web Hosting Provider Targets Python, No...
|
Kirill Boychenko |
2024-10-10 |
879 |
--
|
|
Deno 2.2 Improves Dependency Management and Expands Node.js ...
|
Sarah Gooding |
2025-02-20 |
667 |
--
|
|
Introducing Socket AI – ChatGPT-Powered Threat Analysis - So...
|
Mikola Lysenko |
2023-03-30 |
1,324 |
--
|
|
Malicious npm Package Typosquats Popular TypeScript ESLint P...
|
Socket Research Team |
2024-12-11 |
998 |
--
|
|
Introducing Socket AI Package Summaries
|
Charlie Gerard |
2023-11-21 |
318 |
--
|
|
Skuld Infostealer Returns to npm with Fake Windows Utilities...
|
Kirill Boychenko |
2024-11-08 |
927 |
--
|
|
Introducing Audit Logs for Security and Compliance
|
Philipp Burckhardt |
2023-12-19 |
302 |
--
|
|
Malicious 'akiraa-wb' npm Package Exfiltrates Files to Exter...
|
Socket Research Team |
2024-08-20 |
607 |
--
|
|
The Unpaid Backbone of Open Source: Solo Maintainers Face In...
|
Sarah Gooding |
2024-09-20 |
941 |
--
|
|
rv Is a New Rust-Powered Ruby Version Manager Inspired by Py...
|
Sarah Gooding |
2026-03-03 |
1,075 |
--
|
|
Astral Launches pyx: A Python-Native Package Registry - Sock...
|
Sarah Gooding |
2025-08-13 |
842 |
--
|
|
Adoption of Trusted Publishers Growing Among Open Source Pac...
|
Sarah Gooding |
2024-08-06 |
674 |
--
|
|
Malicious npm Package Targets Ethereum Developers, Masquerad...
|
Socket Research Team |
2024-02-29 |
573 |
--
|
|
UnitedHealth Group Discloses Protected Health Information Co...
|
Sarah Gooding |
2024-04-24 |
735 |
--
|
|
LockBit Dubbed “Cyber Crime Unicorn” After Reports Estimate ...
|
Sarah Gooding |
2024-02-25 |
752 |
--
|
|
JSR Working Group Kicks Off with Ambitious Roadmap and Plans...
|
Sarah Gooding |
2024-11-05 |
912 |
--
|
|
Socket npm Wrapper Feedback Update
|
Bradley Meck Farias |
2023-04-11 |
1,378 |
--
|
|
Open Source Maintainers Demand Ability to Block Copilot-Gene...
|
Sarah Gooding |
2025-05-20 |
1,016 |
--
|
|
Backdooring the IDE: Malicious npm Packages Hijack Cursor Ed...
|
Kirill Boychenko |
2025-05-07 |
957 |
--
|
|
Malicious npm Packages Target BSC and Ethereum to Drain Cryp...
|
Olivia Brown |
2025-06-02 |
963 |
--
|
|
Node.js Adds Experimental Support for TypeScript
|
Sarah Gooding |
2024-07-26 |
543 |
--
|
|
Oxlint Introduces Type-Aware Linting Preview
|
Sarah Gooding |
2025-08-18 |
682 |
--
|
|
Connect with Socket at RSA and BSidesSF 2024
|
Sarah Gooding |
2025-04-23 |
519 |
--
|
|
When "Everything" Becomes Too Much: The npm Package Chaos of...
|
Feross Aboukhadijeh |
2024-01-04 |
745 |
--
|
|
JavaScript Leaders Demand Oracle Release the JavaScript Trad...
|
Sarah Gooding |
2026-03-05 |
764 |
--
|
|
Node.js EOL Versions CVE Dubbed the "Worst CVE of the Year" ...
|
Sarah Gooding |
2025-01-22 |
1,081 |
--
|
|
Malicious npm Package Typosquats react-login-page to Deploy ...
|
Socket Research Team |
2024-07-02 |
886 |
--
|
|
New CNA Scorecard Tool Ranks CVE Data Quality Across the Eco...
|
Sarah Gooding |
2025-08-07 |
1,112 |
--
|
|
Opengrep Launches Playground in Alpha: A Faster, More Stable...
|
Sarah Gooding |
2026-03-24 |
1,040 |
--
|
|
Announcing $20M Series A to Secure Open Source Software - So...
|
Feross Aboukhadijeh |
2023-08-01 |
1,174 |
--
|
|
PyPI Package Disguised as Instagram Growth Tool Harvests Use...
|
Kush Pandya |
2025-06-06 |
1,102 |
--
|
|
Decipher Podcast: How Socket Is Modernizing Tools for Securi...
|
Sarah Gooding |
2023-12-20 |
1,432 |
--
|
|
MCP Spec Updated to Add Structured Tool Output and Improved ...
|
Sarah Gooding |
2025-06-19 |
709 |
--
|
|
TC39 June 2024 Meeting Roundup: 8 Proposals Advanced to Next...
|
Sarah Gooding |
2024-06-13 |
563 |
--
|
|
Understanding the Risks of Trivial Packages in Modern Softwa...
|
Sarah Gooding |
2024-08-22 |
1,217 |
--
|
|
Exposing Automation of npm Registry Spam
|
Socket Research Team |
2023-12-12 |
845 |
--
|
|
2023 State of JavaScript Survey Highlights: Vite Dominates, ...
|
Sarah Gooding |
2023-12-12 |
1,041 |
--
|
|
vlt Launches Real-Time Dependency Analysis Powered by Socket...
|
Sarah Gooding |
2025-04-17 |
323 |
--
|
|
Open Source Maintainers Feeling the Weight of the EU’s Cyber...
|
Sarah Gooding |
2025-07-17 |
1,121 |
--
|
|
NIST Misses 2024 Deadline to Clear NVD Backlog
|
Sarah Gooding |
2024-09-21 |
630 |
--
|
|
Double Whammy: Change Healthcare Targeted Again by RansomHub...
|
Sarah Gooding |
2024-04-09 |
561 |
--
|
|
Python Tools Are Quickly Adopting the New pylock.toml Standa...
|
Sarah Gooding |
2025-04-18 |
664 |
--
|
|
npm Author Qix Compromised via Phishing Email in Major Suppl...
|
Socket Research Team |
2025-09-08 |
432 |
--
|
|
Strengthening Crypto Supply Chain Security Is a Necessity, N...
|
Sarah Gooding |
2026-02-28 |
1,223 |
--
|
|
NPM targeted by malware campaign mimicking familiar library...
|
Socket Research Team |
2025-05-02 |
902 |
--
|
|
Syntax Podcast: "Is Running Random Code From npm Safe?" - So...
|
Sarah Gooding |
2024-01-02 |
284 |
--
|
|
Node.js Takes Steps Towards Removing Corepack
|
Sarah Gooding |
2024-08-08 |
921 |
--
|
|
38% of CISOs Fear They’re Not Moving Fast Enough on AI - …
|
Sarah Gooding |
2025-02-04 |
829 |
--
|
|
2025 Blockchain and Cryptocurrency Threat Report: Malware in...
|
Kirill Boychenko |
2025-06-12 |
1,087 |
--
|
|
Meet the Socket Team at RSAC and BSidesSF 2025
|
Sarah Gooding |
2025-03-27 |
568 |
--
|
|
Malicious PyPI Package Exploits Deezer API for Coordinated M...
|
Kirill Boychenko |
2025-02-25 |
1,072 |
--
|
|
Introducing Organization Dashboards
|
Bret Comnes |
2026-01-23 |
568 |
--
|
|
ESLint Adds Official Support for Linting HTML
|
Sarah Gooding |
2025-05-13 |
575 |
--
|
|
cURL Project and Go Security Teams Reject CVSS as Broken - S...
|
Sarah Gooding |
2025-01-24 |
1,046 |
--
|
|
Weekly Downloads Now Available in npm Package Search Results...
|
Sarah Gooding |
2024-11-26 |
404 |
--
|
|
NIST Announces Major Contract to Clear NVD Backlog by Septem...
|
Sarah Gooding |
2024-06-04 |
994 |
--
|
|
New PyPI Malware ‘set-utils’ Exfiltrates Ethereum Private Ke...
|
Socket Research Team |
2025-01-29 |
611 |
--
|
|
Risky Biz Podcast: How Shifts in Open Source Made It a Prime...
|
Sarah Gooding |
2024-05-01 |
343 |
--
|
|
Destructive npm Packages Disguised as Utilities Enable Remot...
|
Kush Pandya |
2025-06-05 |
1,098 |
--
|
|
Goals for Modern Online File Explorers
|
Bradley Meck Farias |
2023-08-16 |
1,358 |
--
|
|
60 Malicious Ruby Gems Used in Targeted Credential Theft Cam...
|
Kirill Boychenko |
2025-08-07 |
969 |
--
|
|
Squarespace Domain Hijacks Enabled by Email Address Exploit ...
|
Sarah Gooding |
2024-07-16 |
1,017 |
--
|
|
React Team Updates CRA Migration Guidance After Community Pu...
|
Sarah Gooding |
2025-02-19 |
1,081 |
--
|
|
Secure Your AI-Generated Code with Socket MCP
|
Alexandros Kapravelos |
2025-05-28 |
1,254 |
--
|
|
Introducing Go Support
|
Arjun Barrett |
2023-08-02 |
790 |
--
|
|
New Socket Web Extension, Take Socket with You
|
Vincent Grastic |
2024-08-14 |
675 |
--
|
|
Opengrep Emerges as Open Source Alternative Amid Semgrep Lic...
|
Sarah Gooding |
2025-01-23 |
1,225 |
--
|
|
NVD Backlog Tops 20,000 CVEs Awaiting Analysis as NIST Prepa...
|
Sarah Gooding |
2024-11-19 |
748 |
--
|
|
A New Overview in our Dashboard
|
André Staltz |
2025-04-29 |
757 |
--
|
|
Socket and Seal Security Collaborate to Fix Critical npm Ove...
|
Sarah Gooding |
2026-03-20 |
660 |
--
|
|
Introducing Dependency Search
|
Joe Werle |
2023-08-03 |
585 |
--
|
|
Maven Central Adds Sigstore Signature Validation
|
Sarah Gooding |
2026-03-24 |
715 |
--
|
|
npm Updates Search Experience with New Objective Sorting Opt...
|
Sarah Gooding |
2024-12-05 |
709 |
--
|
|
Malicious npm Package Wipes Codebases with Remote Trigger - ...
|
Kush Pandya |
2025-05-30 |
972 |
--
|
|
Create React App Officially Deprecated Amid React 19 Compati...
|
Sarah Gooding |
2025-02-11 |
876 |
--
|
|
Developers Burned by Elasticsearch’s License Change Aren’t G...
|
Sarah Gooding |
2024-09-06 |
1,232 |
--
|
|
Comparing Reachability Analysis Providers
|
Martin Torp |
2024-10-10 |
939 |
--
|
|
From Infra Engineer to CISO: A Conversation with Amplitude’s...
|
Feross Aboukhadijeh |
2025-06-23 |
1,463 |
--
|
|
Socket at BSidesSF and RSA Conference 2023
|
Feross Aboukhadijeh |
2023-04-13 |
253 |
--
|
|
Introducing Socket Firewall: Free, Proactive Protection for ...
|
Dale Bustad |
2025-09-30 |
1,322 |
--
|
|
NIST’s New Password Guidelines Will Eliminate Periodic Chang...
|
Sarah Gooding |
2024-09-26 |
660 |
--
|
|
OpenGrep Restores Fingerprinting in JSON and SARIF Outputs -...
|
Sarah Gooding |
2025-03-31 |
510 |
--
|
|
Redis License Shift Splits Community: Open Source Contributo...
|
Sarah Gooding |
2024-03-27 |
1,273 |
--
|
|
The Cyber Security Council Podcast: Securing Modern Applicat...
|
Sarah Gooding |
2026-03-24 |
408 |
--
|
|
Official Go SDK for MCP in Development, Stable Release Expec...
|
Sarah Gooding |
2025-07-02 |
751 |
--
|
|
Malicious “express-dompurify” npm Package Steals Browser and...
|
Socket Research Team |
2024-09-27 |
1,139 |
--
|
|
GitHub Users Targeted by New Wave of Spambots Promoting Mali...
|
Sarah Gooding |
2024-08-29 |
653 |
--
|
|
Ultralytics PyPI Package Compromised Through GitHub Actions ...
|
Sarah Gooding |
2024-12-10 |
1,236 |
--
|
|
A New Design for GitHub PR Comments
|
André Staltz |
2026-01-23 |
638 |
--
|
|
Deno 2 Improves Compatibility with Node.js and npm, Expands ...
|
Sarah Gooding |
2024-10-10 |
648 |
--
|
|
ECMAScript 2025 Finalized with Iterator Helpers, Set Methods...
|
Sarah Gooding |
2025-06-25 |
560 |
--
|
|
GitHub Actions Supply Chain Attack Puts Thousands of Project...
|
Sarah Gooding |
2025-03-17 |
636 |
--
|
|
Monkey-Patched PyPI Packages Use Transitive Dependencies to ...
|
Kirill Boychenko |
2025-01-26 |
1,056 |
--
|
|
npm Registry Code Signing
|
Bradley Meck Farias |
2023-04-19 |
1,287 |
--
|
|
OpenSSF Report: 75% of New Developers Lack Secure Software S...
|
Sarah Gooding |
2024-09-03 |
1,072 |
--
|
|
CISA’s 2025 SBOM Guidance Adds Hashes, Licenses, Tool Metada...
|
Sarah Gooding |
2025-08-22 |
765 |
--
|
|
Malicious fezbox npm Package Steals Browser Passwords from C...
|
Olivia Brown |
2025-09-22 |
808 |
--
|
|
JSR Now in Public Beta, Aims to Shift Community Towards Usin...
|
Sarah Gooding |
2024-03-02 |
858 |
--
|
|
Two Malicious Rust Crates Impersonate Popular Logger to Stea...
|
Kirill Boychenko |
2025-05-25 |
976 |
--
|
|
ENISA 2024 Threat Landscape Report Warns of Increasing State...
|
Sarah Gooding |
2024-09-27 |
1,084 |
--
|
|
Browserslist-rs Gets Major Refactor, Cutting Binary Size by ...
|
Sarah Gooding |
2026-03-12 |
672 |
--
|
|
From Academia to Industry
|
Philipp Burckhardt |
2024-08-01 |
1,305 |
--
|
|
High Salaries No Longer Enough to Attract Top Cybersecurity ...
|
Sarah Gooding |
2025-03-21 |
791 |
--
|
|
Socket Project Reports v0 Deprecation
|
Alex Morais |
2024-02-16 |
218 |
--
|
|
Introducing .NET Support in Socket
|
Joe Werle |
2025-04-21 |
764 |
--
|
|
Express.js Spam PRs Incident Highlights the Commoditization ...
|
Sarah Gooding |
2024-02-13 |
1,157 |
--
|
|
OSI to Lead Discussions on Navigating the Challenges of Doing Business with …
|
Sarah Gooding |
2024-10-29 |
847 |
--
|
|
Social engineering campaign targeting tech employees spreadi...
|
Feross Aboukhadijeh |
2023-07-25 |
1,191 |
--
|
|
npm Malware Targets Telegram Bot Developers with Persistent ...
|
Kush Pandya |
2025-04-18 |
797 |
--
|
|
Introducing Dependency Visualization: An Interactive Way to ...
|
Eli Insua |
2026-01-23 |
413 |
--
|
|
Massive Automated Spam Campaign Abuses GitHub to Flood npm R...
|
Sarah Gooding |
2024-07-11 |
616 |
--
|
|
Roblox Developers Targeted with npm Packages Infected with S...
|
Kirill Boychenko |
2024-11-08 |
1,124 |
--
|
|
The Wildcard Gamble: Understanding the Risks of Floating Dep...
|
Sarah Gooding |
2024-09-13 |
1,225 |
--
|
|
wget to Wipeout: Malicious Go Modules Fetch Destructive Payl...
|
Kush Pandya |
2025-05-01 |
885 |
--
|
|
The “Skeleton Squad” is now targeting NPM
|
Socket Research Team |
2023-04-18 |
629 |
--
|
|
CVE Publication Hits All-Time High: 5,000+ Vulnerabilities R...
|
Sarah Gooding |
2024-06-08 |
851 |
--
|
|
Socket secures $40M to combat next-generation software suppl...
|
Feross Aboukhadijeh |
2024-10-22 |
733 |
--
|
|
Kill Switch Hidden in npm Packages Typosquatting Chalk and C...
|
Kush Pandya |
2025-01-13 |
1,043 |
--
|
|
Fluent Assertions Faces Backlash After Abandoning Open Sourc...
|
Sarah Gooding |
2026-04-02 |
1,082 |
--
|
|
Vite Releases Technical Preview of Rolldown-Vite, a Rust-Bas...
|
Sarah Gooding |
2025-05-30 |
811 |
--
|
|
CISA Announces Initiative to Fortify Security of Open Source...
|
Sarah Gooding |
2026-03-03 |
635 |
--
|
|
Socket Now Supports pylock.toml Files
|
Trevor Norris |
2025-06-05 |
989 |
--
|
|
Node.js Moves Toward Stable TypeScript Support with Amaro 1....
|
Sarah Gooding |
2025-06-10 |
535 |
--
|
|
Bybit Hack Puts Crypto Losses at $1.6B, Surpassing All of La...
|
Sarah Gooding |
2025-03-03 |
1,019 |
--
|
|
OpenSSF Launches Open Source Project Security Baseline to St...
|
Sarah Gooding |
2025-02-28 |
999 |
--
|
|
How to Mitigate the Risks of Using Open Source Packages with...
|
Sarah Gooding |
2024-07-26 |
1,181 |
--
|
|
Oxlint Now in Beta with 500+ Built-in Rules and 2X Faster Ja...
|
Sarah Gooding |
2025-03-18 |
735 |
--
|
|
Introducing Socket MCP for Claude Desktop
|
Alexandros Kapravelos |
2025-07-29 |
839 |
--
|
|
Understanding License Exceptions: What Developers Need to Kn...
|
Sarah Gooding |
2024-09-20 |
1,168 |
--
|
|
A Fresh Look for the Socket Dashboard
|
Joe Werle |
2025-06-23 |
579 |
--
|
|
Identifying and Preventing Fraudulent Engineering Candidates...
|
Socket Research Team |
2025-09-17 |
1,202 |
--
|
|
Sonar to Acquire Tidelift, Scaling Open Source Maintainer Su...
|
Sarah Gooding |
2024-12-18 |
750 |
--
|
|
Meet Socket at BlackHat and DEF CON in Las Vegas
|
Amjed Aboukhadijeh |
2024-07-20 |
456 |
--
|
|
Malicious Maven Package Impersonating 'XZ for Java' Library ...
|
Kirill Boychenko |
2024-05-12 |
1,078 |
--
|
|
Unveiling Members Hub: A Large-Scale Campaign to Artificiall...
|
Kush Pandya |
2024-10-02 |
755 |
--
|
|
Malicious Python Package Typosquats Popular 'fabric' SSH Lib...
|
Socket Research Team |
2024-11-06 |
953 |
--
|
|
ua-parser-js Drops MIT License, Adopts Controversial AGPLv3 ...
|
Sarah Gooding |
2024-06-18 |
816 |
--
|
|
Trojan Embedded in crytic-compilers Python Package Targets P...
|
Kush Pandya |
2024-06-04 |
569 |
--
|
|
Tech's $90B Ghost Engineer Problem: Stanford Study Finds 9.5...
|
Sarah Gooding |
2026-03-24 |
772 |
--
|
|
Using Trusted Protocols Against You: Gmail as a C2 Mechanism...
|
Olivia Brown |
2025-04-30 |
1,002 |
--
|
|
Interview on the Daytona DotFiles Insider Blog
|
Sarah Gooding |
2026-02-26 |
233 |
--
|
|
UK Officials Consider Banning Ransomware Payments from Publi...
|
Sarah Gooding |
2025-04-08 |
565 |
--
|
|
socket.yml v2 now available
|
Joe Werle |
2026-01-23 |
415 |
--
|
|
Introducing Module Reachability: Focus on the Vulnerabilitie...
|
Trevor Norris |
2025-04-23 |
656 |
--
|
|
Author Typosquatting on npm: Attackers Impersonate Sindre So...
|
Kirill Boychenko |
2024-10-31 |
979 |
--
|
|
Risky Business Podcast: Why Open Source Software Needs Bette...
|
Sarah Gooding |
2026-02-26 |
396 |
--
|
|
NVD Remains Stalled on Enriching CVE's, Security Industry Cr...
|
Sarah Gooding |
2024-04-05 |
1,048 |
--
|
|
Project Health Reports now run on the default branch - Socke...
|
Bret Comnes |
2023-05-03 |
116 |
--
|
|
Orbit Bridge Hackers Drain $81 Million in Crypto Assets - So...
|
Sarah Gooding |
2024-01-03 |
623 |
--
|
|
PyTorch Lightning Exposes Users to Remote Code Execution via...
|
Sarah Gooding |
2025-04-03 |
535 |
--
|
|
White House Report Highlights Persistent Challenges and Urge...
|
Sarah Gooding |
2024-08-13 |
1,153 |
--
|
|
vlt Launches "reproduce": A New Tool Challenging the Limits ...
|
Sarah Gooding |
2025-02-26 |
877 |
--
|
|
Black Basta’s Dependency Confusion Ambitions and Ransomware ...
|
Kirill Boychenko |
2025-02-24 |
1,112 |
--
|
|
Malicious npm Packages Target WhatsApp Developers with Remot...
|
Kush Pandya |
2025-08-06 |
1,057 |
--
|
|
New Research Shows Teams of LLM Agents Can Autonomously Expl...
|
Sarah Gooding |
2024-06-11 |
777 |
--
|
|
Typosquatting on PyPI: Malicious Package Mimics Popular 'bro...
|
Kirill Boychenko |
2024-10-11 |
882 |
--
|
|
Protestware in JavaScript UI Toolkits on npm Target Russian ...
|
Olivia Brown |
2025-06-17 |
1,009 |
--
|
|
How Hackers are Using Package Managers as Vectors for Deploy...
|
Sarah Gooding |
2024-01-05 |
715 |
--
|
|
Github App Improvements
|
Bret Comnes |
2022-07-26 |
523 |
--
|
|
Introducing Repository Labels and Security Policies
|
Nolan Lawson |
2025-04-22 |
488 |
--
|
|
Cyber Extortion Demands Skyrocket in 2023 While Fewer Compan...
|
Sarah Gooding |
2026-02-24 |
589 |
--
|
|
CISA Extends MITRE Contract as Crisis Accelerates Alternativ...
|
Sarah Gooding |
2025-04-16 |
788 |
--
|
|
Contagious Interview Campaign Escalates With 67 Malicious np...
|
Kirill Boychenko |
2025-07-14 |
1,113 |
--
|
|
Linux Foundation Warns Open Source Developers: Compliance wi...
|
Sarah Gooding |
2025-02-06 |
1,001 |
--
|
|
Socket Joins TC54 to Help Shape the Future of SBOMs, Cyclone...
|
Sarah Gooding |
2025-01-31 |
532 |
--
|
|
Malicious PyPI Package ‘pycord-self’ Targets Discord Develop...
|
Socket Research Team |
2023-04-08 |
620 |
--
|
|
The Dark Side of Open Source
|
Sarah Gooding |
2024-04-19 |
441 |
--
|
|
npm bin script confusion: Abusing ‘bin’ to hijack ‘node’ com...
|
Kush Pandya |
2022-10-19 |
1,152 |
--
|
|
Silent Discord Raider: 'Blank Grabber’ Python Package Steals...
|
Kush Pandya |
2023-12-26 |
1,011 |
--
|
|
Input Validation Vulnerabilities Dominate MITRE's 2024 CWE T...
|
Sarah Gooding |
2024-11-22 |
768 |
--
|
|
Socket Acquires Coana to Bring Reachability Analysis to Ever...
|
Feross Aboukhadijeh |
2025-04-23 |
1,242 |
--
|
|
Introducing Ruby Support in Socket
|
Joe Werle |
2024-10-21 |
933 |
--
|
|
Node.js Implements Stricter Policies for Semver-Major Pull R...
|
Sarah Gooding |
2024-11-08 |
559 |
--
|
|
npm Package for ReExt React Components Library Exfiltrates G...
|
Kush Pandya |
2024-04-18 |
738 |
--
|
|
Socket CLI v0.9.0 Now Available
|
Charlie Gerard |
2023-12-01 |
319 |
--
|
|
Wallet-Draining npm Package Impersonates Nodemailer to Hijac...
|
Kirill Boychenko |
2025-08-29 |
837 |
--
|
|
Socket for GitHub v2 Introduces Diff Reports, Speeds Up Scan...
|
Sarah Gooding |
2024-01-24 |
447 |
--
|
|
$4.6M Series Seed to defend open source from supply chain at...
|
Feross Aboukhadijeh |
2022-05-11 |
1,130 |
--
|
|
Researchers Uncover npm Registry Vulnerability to Cache Pois...
|
Sarah Gooding |
2024-06-15 |
837 |
--
|
|
Introducing Organization Alerts: See Your Dependency Risks Across All Repositories
|
Joe Werle |
2023-12-21 |
836 |
--
|
|
Crates.io Users Targeted by Phishing Emails
|
Sarah Gooding |
2025-09-12 |
389 |
--
|
|
Introducing Socket Optimize
|
John-David Dalton |
2024-10-16 |
711 |
--
|
|
npm in Review: A 2023 Retrospective on Growth, Security, and...
|
Philipp Burckhardt |
2024-01-10 |
1,045 |
--
|
|
Rust Support Now in Beta
|
Joe Werle |
2025-09-11 |
517 |
--
|
|
ESLint is Now Language-Agnostic: Linting JSON, Markdown, and...
|
Sarah Gooding |
2024-10-03 |
599 |
--
|
|
GitHub Activates Push Protection by Default After Detecting ...
|
Sarah Gooding |
2026-03-24 |
668 |
--
|
|
MITRE Marks Major Milestone, Minting 400 CNAs as NVD Backlog...
|
Sarah Gooding |
2024-02-12 |
913 |
--
|
|
Typosquatting Cryptographic Libraries: Malicious npm Package...
|
Kirill Boychenko |
2024-11-27 |
962 |
--
|
|
Lazarus Strikes npm Again with New Wave of Malicious Package...
|
Kirill Boychenko |
2025-03-10 |
1,052 |
--
|
|
Announcing: Socket CLI Preview
|
Pelle Wessman |
2022-11-17 |
970 |
--
|
|
Critical Vulnerability in NestJS Devtools: Localhost RCE via...
|
Jonathan Leitschuh |
2025-08-01 |
1,288 |
--
|
|
ALPHV/Blackcat Ransomware Group Fires Back with Escalated Ho...
|
Sarah Gooding |
2023-12-21 |
590 |
--
|
|
New axobject-query Maintainer Faces Backlash Over Controvers...
|
Sarah Gooding |
2024-06-25 |
1,188 |
--
|
|
Socket Now Available on Google Cloud Marketplace
|
Sarah Gooding |
2025-03-21 |
374 |
--
|
|
GitHub App Permission Update (Jan 2023)
|
Bret Comnes |
2023-01-09 |
202 |
--
|
|
Introducing License Enforcement in Socket
|
Philipp Burckhardt |
2024-10-17 |
837 |
--
|
|
Announcing Socket Fix 2.0
|
Joe Werle |
2025-09-10 |
873 |
--
|
|
Introducing Custom Pull Request Alert Comment Headers - Sock...
|
André Staltz |
2026-01-23 |
496 |
--
|
|
Why Socket is the Best Tool for Developers to Stop Supply Ch...
|
Feross Aboukhadijeh |
2023-08-08 |
862 |
--
|
|
Python Software Foundation Responds to GitHub Token Leak, El...
|
Sarah Gooding |
2024-07-17 |
546 |
--
|
|
Announcing Self-Service Payment Plans
|
Joe Werle |
2023-08-24 |
646 |
--
|
|
Software Supply Chain Compromise Now the Top Threat of the N...
|
Sarah Gooding |
2024-04-02 |
584 |
--
|
|
Quasar RAT Disguised as an npm Package for Detecting Vulnera...
|
Kirill Boychenko |
2024-12-18 |
814 |
--
|
|
ESLint Adds Support for Parallel Linting, Closing 10-Year-Ol...
|
Sarah Gooding |
2025-08-22 |
490 |
--
|
|
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
|
Sarah Gooding |
2025-01-10 |
802 |
--
|
|
Socket Now Supports uv.lock Files
|
Trevor Norris |
2025-01-09 |
903 |
--
|
|
TC39 Advances Key Proposals: Deferred Import Evaluation, Err...
|
Sarah Gooding |
2024-06-11 |
647 |
--
|
|
Package Maintainers Call for Improvements to GitHub’s New np...
|
Sarah Gooding |
2025-09-30 |
1,111 |
--
|
|
Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader
|
Socket Research Team |
2026-07-14 |
2,318 |
--
|
|
11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows …
|
Kush Pandya |
2026-07-14 |
4,726 |
--
|
|
Next.js moves to scheduled security releases
|
Sarah Gooding |
2026-07-16 |
869 |
--
|
|
Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Music Scraping
|
Sarah Gooding |
2026-07-16 |
491 |
--
|
|
White House Launches Gold Eagle Initiative to Manage Surge in AI-Discovered Vulnerabilities
|
Sarah Gooding |
2026-07-17 |
936 |
--
|
|
New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs
|
Sarah Gooding |
2026-07-22 |
1,200 |
--
|
|
Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign
|
Kirill Boychenko |
2026-07-22 |
2,203 |
--
|
|
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
|
Kirill Boychenko |
2026-07-24 |
943 |
--
|
|
The AI Industry Is Betting on Open Weights
|
Sarah Gooding |
2026-07-27 |
928 |
--
|
|
Socket Releases Free Certified Patches for Nuxt Security Vulnerabilities
|
Wenxin Jiang |
2026-07-27 |
619 |
--
|
|
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
|
Socket Research Team |
2026-07-28 |
2,331 |
--
|
|
Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers
|
Karlo Zanki |
2026-07-28 |
2,202 |
--
|
|
Socket Is Sponsoring Composer and Packagist
|
Sarah Gooding |
2026-07-31 |
436 |
--
|
|
Claude Breached 3 Companies and Uploaded Malware to PyPI During Anthropic's Security …
|
Sarah Gooding |
2026-07-31 |
1,119 |
--
|
|
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active …
|
Socket Research Team |
2026-08-04 |
2,073 |
--
|