Home / Companies / Socket / Blog / November 2025

November 2025 Summaries

17 posts from Socket

Filter
Month: Year:
Post Summaries Back to Blog
North Korea's Contagious Interview operation has intensified its infiltration of the npm ecosystem, expanding with at least 197 new malicious packages and over 31,000 additional downloads, targeting blockchain and Web3 developers via fake job interviews and test assignments. This prolific campaign leverages a sophisticated infrastructure involving GitHub, Vercel, and command and control servers to deliver OtterCookie malware, which performs a range of malicious activities such as keylogging, clipboard theft, and the exfiltration of crypto-wallet data. The operation involves typosquatted npm packages like tailwind-magic, which masquerade as legitimate utilities while executing threat actor-supplied code. Despite the removal of the GitHub account stardev0914, the techniques and infrastructure continue to evolve, with the campaign adapting to modern development workflows. Security measures are recommended, including the hardening of CI environments, network egress controls, and rigorous review processes for new templates and dependencies to mitigate the risk of such supply chain attacks.
Nov 26, 2025 5,010 words in the original blog post.
Socket's Threat Research Team has identified a malicious Chrome extension named Crypto Copilot, marketed as a tool for executing Solana trades directly from Twitter feeds. The extension injects an additional transfer fee into every Solana swap, sending a minimum of 0.0013 SOL or 0.05% of the trade amount to a hardcoded attacker-controlled wallet, without disclosure on the Chrome Web Store listing. The fee injection is hidden within heavily obfuscated code, making it difficult for users to detect the unauthorized transfer. Crypto Copilot connects with popular Solana wallets and uses various legitimate services to create a façade of authenticity, while the backend infrastructure lacks genuine functionality, indicating a malicious intent. The extension's marketing focuses on convenience and speed, but omits mention of the hidden fees, which are rarely noticed due to their integration into normal swap transactions. The extension remains available, and Socket has requested its removal from the Chrome Web Store, advising users to review transactions carefully and avoid similar extensions.
Nov 25, 2025 1,517 words in the original blog post.
PostHog's GitHub Actions workflow was exploited as an entry point for the Shai Hulud v2 campaign, leading to a compromise that allowed attackers to steal GitHub secrets and publish malicious versions of PostHog SDKs. The campaign, primarily targeting the npm ecosystem, has extended into the Java/Maven ecosystem, compromising hundreds of packages and exposing secrets from thousands of GitHub repositories. The malware utilizes a two-stage loader to execute a stealthy payload that installs the Bun runtime, collects system information, and exploits CI/CD environments for privilege escalation. It exfiltrates data using a GitHub repository created with stolen tokens, employing triple-base64 encoding to evade detection. The attack highlights the vulnerabilities in CI/CD workflows, emphasizing the need for stricter security measures and vigilant monitoring of package dependencies.
Nov 24, 2025 3,910 words in the original blog post.
The European Union Agency for Cybersecurity (ENISA) has been elevated to a CVE Program Root, joining the ranks of MITRE, CISA, and other global cybersecurity leaders. This advancement enhances ENISA's role in the European cybersecurity landscape, allowing it to act as a central authority for coordinating vulnerability management and reporting across the EU. As a CVE Root, ENISA will oversee European CVE Numbering Authorities, facilitate cross-border collaboration, and integrate its efforts with initiatives like the European Vulnerability Database and the Cyber Resilience Act's Single Reporting Platform. This strategic move aims to harmonize vulnerability reporting, reduce global bottlenecks in the CVE ecosystem, and support the EU's push for independence in vulnerability governance, ensuring that vulnerabilities affecting multiple member states are managed consistently and effectively.
Nov 21, 2025 566 words in the original blog post.
Socket has introduced Webhook Events for Alert Changes, offering real-time notifications for alert lifecycle changes, which enhance the monitoring of software supply chains. These alerts track changes across repositories and can trigger automated workflows, allowing users to respond faster without constantly checking dashboards. Alerts can change due to newly merged pull requests, new threats, or modified security policies, even if the code and SBOMs remain unchanged. Each webhook event includes comprehensive alert details, such as the type of change, alert status, timestamps, and links to further information. Webhooks facilitate real-time updates between systems by sending HTTP requests for specific events, allowing seamless integration with tools like Slack, Jira, and CI pipelines to automate workflows. The new alert IDs are initially available via webhooks and will soon be accessible throughout the Socket dashboard. Socket's Webhook Events for Alert Changes are now available for Business and Enterprise customers, with additional features planned to further integrate Socket into workflows and enhance dependency security management.
Nov 21, 2025 728 words in the original blog post.
Socket has introduced experimental support for scanning the OpenVSX ecosystem, offering proactive security analysis for VS Code compatible extensions to help teams identify risky capabilities, malicious behaviors, and vulnerabilities before these extensions are installed on developer machines. This initiative addresses the significant security risks associated with extensions, which have broad access to code, environments, and developer credentials, and can become potential vectors for attacks if compromised. Recent studies and attacks have highlighted the vulnerabilities within the extension ecosystem, such as the presence of backdoors and leaked secrets, underscoring the need for tools like Socket to provide visibility into an extension's behavior prior to installation. By scanning extensions for unsafe activity using AI malware detection and specific heuristics, Socket aims to mitigate potential security threats in developer tools, enhancing the resilience of the software supply chain as attackers increasingly target developer resources. The OpenVSX scanning feature is currently available in an experimental phase for select organizations, with plans for wider availability and continued development to include support for the VS Code Marketplace, ultimately aiming for comprehensive extension ecosystem coverage.
Nov 20, 2025 954 words in the original blog post.
Socket has announced beta support for the emerging JavaScript package managers Bun and vlt, providing comprehensive supply chain protection and SBOM accuracy for teams using these tools. Known for its early support of innovative package management solutions, Socket extends its capabilities beyond established platforms like npm and Yarn, now including Bun's high-performance features and vlt's serverless registry approach. This move ensures developers do not have to compromise on security while adopting new technologies. Socket automatically detects lockfiles such as bun.lock and vlt-lock.json, analyzes dependency graphs, and provides real-time security monitoring, making it easier for development teams to explore and implement these modern tools. While certain limitations remain, such as lack of support for binary Bun lockfiles, the beta release aims to gather user feedback for future improvements. With this early rollout, Socket emphasizes the importance of keeping security measures aligned with the rapid innovation in the JavaScript ecosystem, helping developers confidently integrate new package managers into their workflows.
Nov 19, 2025 687 words in the original blog post.
Socket Certified Patches provide a novel solution for addressing vulnerabilities in the JavaScript ecosystem without the need for upgrading dependencies, thus reducing the risk of introducing new, unvetted code. These patches offer a one-click, low-impact remediation by applying small, targeted fixes directly to existing code, thereby preserving package behavior and ensuring stability. This approach is particularly beneficial in the wake of recent supply-chain attacks, where traditional dependency updates have proven to be risky, potentially pulling in malicious updates. Socket Certified Patches, supported by a robust review and validation process, allow teams to remove vulnerabilities swiftly and securely while maintaining operational normalcy. Currently available in closed beta for JavaScript and TypeScript, with plans to expand, Socket Certified Patches aim to create a more resilient open-source ecosystem by mitigating risks without destabilizing production systems.
Nov 18, 2025 1,420 words in the original blog post.
The Socket Threat Research Team uncovered a sophisticated malware campaign by a threat actor named dino_reborn, who deployed seven npm packages to target victims with malicious software. These packages, including names like dsidospsodlks and integrator-2829, utilize tactics such as anti-analysis techniques and traffic cloaking through the use of Adspect, a service typically used in malvertising, to evade detection by security researchers. The malware identifies visitors to its fake website, displaying a malicious CAPTCHA to suspected victims while showing harmless content to researchers. The campaign is linked to crypto-related sites, suggesting a possible goal of cryptocurrency theft, and employs a fake company webpage to add legitimacy. The packages remain live on npm, despite takedown requests, and the threat actor's tactics indicate a growing trend of using open-source distribution to mask malicious activities. Security teams are advised to monitor for specific indicators, such as unusual scripts and Adspect-related endpoints, to mitigate the risk of such attacks.
Nov 17, 2025 3,290 words in the original blog post.
Security teams are overwhelmed with numerous CVEs, and while upgrading dependencies is time-consuming and risky, prioritizing vulnerabilities that can be exploited within an application can save significant time and effort. Socket's reachability engine, already effective for JavaScript/TypeScript and Python, is now available in beta for Ruby, despite its dynamic nature posing challenges for deep reachability analysis. The engine uses function-level call graph analysis to determine which functions may call vulnerable ones, ensuring no exploitable issues are overlooked by classifying uncertainties as reachable or unknown. This approach, developed in collaboration with Aarhus University, builds on previous experiences with dynamic languages and addresses Ruby's frequent use of runtime class modification in meta-programming. While the Ruby reachability support is still in beta and may occasionally fail due to unexpected conditions, Socket is continuously improving it and welcomes community feedback. Users can access this analysis via pre-computed results on the Socket Dashboard or through the Socket CLI for enterprise customers, marking a step towards expanding precise, function-level analysis across major ecosystems.
Nov 17, 2025 572 words in the original blog post.
PyPI's Trusted Publishing feature has expanded to include GitLab Self-Managed instances, further enhancing security by allowing CI platforms to publish packages without permanent API tokens through short-lived tokens issued via an OpenID Connect trust relationship. This extension, now in beta, follows the successful adoption by GitHub Actions and GitLab.com, with more than 45,000 projects enabled since its 2023 inception. The update also introduces organization-level ownership control, preventing ownership drift in multi-maintainer environments. Meanwhile, the Python Software Foundation (PSF) recently declined a $1.5M U.S. National Science Foundation grant due to conditions conflicting with its DEI mission, sparking community support that raised over $160,000 in donations. The PSF is at a "critical inflection point" regarding PyPI's sustainability, managing 2-3 billion daily requests, and is seeking multi-year infrastructure partnerships and optional paid features to support ongoing improvements in software supply chain security.
Nov 14, 2025 644 words in the original blog post.
A recent npm spam campaign, inaccurately labeled as a "worm," is actually a continuation of a long-standing pattern of spam activity linked to the TEA Protocol's crypto reward scheme, which Socket has been monitoring for nearly two years. The campaign's goal is to artificially inflate the number of dependents for spam projects by creating fake dependency networks using random package names and tea.yaml files. Although some have described the campaign's characteristics as worm-like due to dependency chain spreading and a replicating publish script, these do not constitute true worm behavior, as there is no autonomous execution or malicious payload involved. The spam packages, which use random Indonesian food names rather than typosquatting popular ones, have not compromised accounts or spread maliciously. Despite generating significant operational friction by consuming registry resources and complicating automated malware detection, the campaign poses no direct security threat to developers. Efforts by individuals like Paul McCarty and organizations such as OpenSSF, which assigned malicious package identifiers and took down the spam packages, are crucial to maintaining the integrity of package registries.
Nov 14, 2025 929 words in the original blog post.
Socket's Threat Research Team has identified a malicious Chrome extension called Safery: Ethereum Wallet, which masquerades as a secure Ethereum wallet but contains a backdoor that exfiltrates users' seed phrases. This is achieved by encoding the BIP-39 mnemonic into synthetic Sui addresses and sending microtransactions from a threat actor-controlled Sui wallet, allowing the threat actor to reconstruct the original mnemonic and potentially drain the user's assets. The extension, which appears legitimate alongside popular wallets like MetaMask on the Chrome Web Store, uses blockchain transactions to conceal the mnemonic exfiltration without HTTP traffic or a central control server. This method allows threat actors to switch between different blockchain networks with ease, making it difficult to detect using traditional methods. Recommendations include using only trusted wallet extensions, monitoring unexpected blockchain RPC calls, and employing tools like Socket's Chrome extension protection to detect and block risky behaviors.
Nov 12, 2025 1,371 words in the original blog post.
In December, the Socket team will attend two major security events in London, Black Hat Europe and BSides London, to discuss software supply chain security and demonstrate how their solutions help teams manage open source dependencies. The team highlights the increasing threat of supply chain attacks targeting developers through compromised dependencies and malicious scripts. To address these threats, Socket has introduced Socket Firewall Enterprise, offering configurable policies and on-premise deployment to protect developers at the installation stage. They have also enhanced their reachability analysis to help teams focus on critical vulnerabilities, reducing alert noise by up to 80%. Attendees are encouraged to book meetings with the Socket team to explore their latest features and engage directly with their engineers during these events.
Nov 11, 2025 338 words in the original blog post.
The OWASP Top 10 for 2025 introduces a new category, Software Supply Chain Failures, reflecting the growing recognition of risks in the tools and infrastructure used to build and deliver software, beyond just outdated components. This update marks a significant shift, as 50% of survey respondents identified it as their top concern, and it had the highest average incidence rate despite minimal CVE coverage. The report highlights how supply chain threats, such as compromised packages and CI/CD pipeline intrusions, pose substantial security risks. By grouping related Common Weakness Enumerations (CWEs) into broader categories, OWASP aims to provide a more relevant framework across diverse technology stacks, emphasizing the importance of managing dependencies and securing development processes. This new focus underscores the need for visibility, integrity, and strong access controls in managing supply chain risks, encouraging a cultural shift where dependencies and build pipelines are integral to the threat model rather than trusted by default.
Nov 08, 2025 896 words in the original blog post.
Socket's Threat Research Team identified nine malicious NuGet packages published under the alias "shanhai666" that pose a significant threat to database operations and industrial control systems by injecting time-delayed destructive payloads. These packages, including the notably hazardous Sharp7Extend, employ dual sabotage mechanisms—random process termination and silent write failures—to compromise safety-critical systems. Released between 2023 and 2024, the packages have accumulated 9,488 downloads and target major database providers used in .NET applications, as well as industrial PLCs. The malicious code is concealed within extensive legitimate functionality, which builds trust among developers and delays detection. The packages exploit C# extension methods to seamlessly integrate destructive logic into operations, activating based on specific trigger dates in 2027 and 2028. This strategic approach, combined with tactics like typosquatting and the use of legitimate code, complicates detection and attribution, making forensic investigations challenging. Organizations are urged to audit dependencies for these packages, as they are advised to assume any system with them is compromised, particularly those using the Sharp7Extend package in industrial environments, which may already be experiencing the effects of the sabotage mechanisms disguised as routine operational failures.
Nov 06, 2025 2,255 words in the original blog post.
At the Enterprise Ready Conf 2025, Socket CTO Ahmad Nassri and WorkOS's Michael Chan discussed the evolving security challenges faced by developers, emphasizing the need for proactive measures against rapidly advancing supply chain attacks and sophisticated social engineering. Nassri highlighted that traditional security approaches are insufficient as modern attacks target developer tools and environments, such as Chrome extensions and IDE plugins, necessitating immediate protection at the point of installation. The conversation also included a panel featuring industry experts who deliberated on the impact of AI, compliance, and fast-paced development on enterprise readiness. They concluded that while fundamental security principles remain crucial, they must now extend to AI agents and developer environments. Furthermore, the panelists noted how startups are leveraging compliance as a competitive edge, the growing importance of "secure by default" policies, and the evolving role of developers as AI tools increasingly empower various business functions.
Nov 04, 2025 267 words in the original blog post.