Home / Companies / Socket / Blog / September 2022

September 2022 Summaries

1 posts from Socket

Filter
Month: Year:
Post Summaries Back to Blog
Socket, a security-focused company, has been protecting against "manifest confusion" attacks within the npm ecosystem since September 2022, months before the issue was publicly highlighted by former GitHub engineer Darcy Clarke. Manifest confusion refers to the potential security risk arising from the independent publication of a package's manifest and its tarball, allowing attackers to hide malicious scripts and dependencies that escape detection by traditional security tools. Socket addressed this vulnerability by ensuring its dependency analysis aligns with the actual contents of the package, thereby preventing exploitation. The company has also introduced a proactive detection feature to alert users of suspicious activities, encouraging other security tool vendors to enhance their accuracy and reliance on package contents for metadata. Socket's efforts underscore the importance of robust software composition analysis (SCA) tools to safeguard the software supply chain, while also inviting users to install their solution from the GitHub Marketplace for immediate protection.
Sep 05, 2022 710 words in the original blog post.