Home / Companies / Socket / Hacker News

Socket on HN

412 posts with 1+ points since 2022

Filters
Since:
Posts by Month (412 total)
Hacker News Posts
Title Points Comments Date
Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised 1,233 1,019 2025-09-16
Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign 872 432 2026-04-23
Trivy under attack again: Widespread GitHub Actions tag compromise secrets 250 83 2026-03-22
NPM to implement staged publishing after turbulent shift off classic tokens 205 125 2026-01-07
The Everything NPM Package 192 151 2024-01-06
Show HN: Socket – Secure your JavaScript supply chain 133 42 2022-03-01
The push to ban ransom payments is gaining momentum 127 166 2024-05-22
Social engineering campaign targeting tech employees spreads through NPM malware 114 87 2023-07-25
Active NPM supply chain attack: Tinycolor and 40 Packages Compromised 85 36 2025-09-15
German Court Fines Security Researcher for Reporting Company's Vulnerabilities 77 34 2024-01-23
OpenJS: "XZ Utils Cyberattack Likely Not an Isolated Incident" 65 25 2024-04-17
What's Going on Inside Your Node_modules Folder? 64 33 2022-03-02
Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware 62 39 2026-08-07
Chinese devs are storing 1000s of eBooks on GitHub and NPM 62 12 2022-11-06
Unverified NPM Account Takeover Vulnerability for Sale on Dark Web Forum 53 4 2024-07-06
Prettier NPM Packages Compromised in Supply Chain Attack 45 7 2025-07-19
Namecheap Takes Down Polyfill.io Service Following Supply Chain Attack 42 9 2024-06-26
Curl Project and Go Security Teams Reject CVSS as Broken 40 10 2025-01-24
Gem.Coop – Community-Run Alternative to Rubygems.org, Led by Former Maintainers 30 3 2025-10-06
DuckDB NPM Account Compromised in Continuing Supply Chain Attack 27 1 2025-09-09
Libxml2 Maintainer Ends Embargoed Vulnerability Reports, Citing Unsustainable 27 8 2025-06-18
Automated Spam Campaign Floods GitHub/NPM with 1000s of Garbage Packages 25 4 2024-07-12
New Rust RFC Proposes Adding Support for Trusted Publishing to Crates.io 24 13 2024-09-12
New Proposed CISA Mandate Would Require Critical Infrastructure to Report Ransom 19 1 2024-03-29
Malicious Postinstall Hook Found in 700 GitHub Repos, Including Node Projects 18 4 2026-05-23
Supply Chain Attack Detected in Solana/Web3.js Library 17 0 2024-12-03
Go Supply Chain Attack: Malicious Package Exploits Go Module 17 0 2025-02-05
AI Agent Lands PRs in Major OSS Projects, Targets Maintainers via Cold … 16 1 2026-02-14
Open Source Maintainers Demand Ability to Block Copilot-Generated Issues and PRs 14 0 2025-05-20
NPM 'Is' Package Hijacked in Expanding Supply Chain Attack 14 0 2025-07-22
$4.6M Series Seed to defend open source from supply chain attacks 14 3 2022-05-12
Researcher Exposes 0-Day Clickjacking Vulnerabilities in Major Password Managers 13 5 2025-08-19
Express.js Spam PRs Highlight the Commoditization of Open Source Contributions 13 0 2024-02-13
Socket AI – Scan every NPM and PyPI package for malware with … 13 1 2023-03-31
Supply Chain Attacks Targeting LLM Application Developers: The Hidden Dangers Of 12 2 2024-10-24
Threat Actor Exposes Playbook for Exploiting NPM to Build Blockchain-Powered 11 0 2024-11-19
The Rise of Slopsquatting 11 4 2025-04-10
Typosquatted Go Packages Deliver Malware Loader Targeting Linux and macOS 11 1 2025-03-04
AI Slop Is Polluting Bug Bounty Platforms with Fake Vulnerability Reports 11 2 2025-05-07
Socket, an open source supply chain security platform 11 0 2022-03-01
NIST's New Password Guidelines Will Eliminate Periodic Changes and Special 11 1 2024-09-26
Contagious Interview Campaign Escalates with 67 Malicious NPM Packages and New 10 3 2025-07-14
Shai-Hulud-Style NPM Worm Hijacks CI Workflows and Poisons AI Toolchains 10 0 2026-02-21
Wget to Wipeout: Malicious Go Modules Fetch Destructive Payload 10 0 2025-05-01
The GitHub Infrastructure Powering North Korea's Contagious Interview NPM Attack 10 1 2025-11-29
Node.js Community Debate Intensifies over Potentially Unbundling NPM 9 None 2024-02-08
Popular Rust Crates Compromised in Build-Time Supply Chain Attack 9 2 2026-08-21
Redis License Shift Splits Community: Open-Source Contributors Move to Fork 9 None 2024-03-27
Free Software Foundation Goes to Bat for AGPL in Amicus Brief Criticizing 9 None 2025-03-06
Laravel Lang Compromised with RCE Backdoor Across 700 Versions 9 1 2026-05-23
"Valkey" Open Source Redis Fork Backed by Linux Foundation, Amazon, Google 8 None 2024-03-29
Judicious JSON 8 None 2024-01-04
PyPI Now Supports iOS and Android Wheels for Mobile Python Development 8 None 2025-02-12
New Website "Is It FOSS?" Tracks Transparency in Open Source Distribution 8 None 2025-08-16
Python Adopts Standard Lock File Format for Reproducible Installs 8 None 2025-04-01
Socket Firewall: Free, Proactive Protection for Your Software Supply 8 None 2025-09-30
Rust Support in Socket 8 None 2025-07-31
.NET Support in Socket 7 None 2025-04-21
Malicious Go Packages Impersonate Google's UUID Library and Exfiltrate Data 7 None 2025-12-05
Malicious Chrome Extension Steals MEXC API Keys for Account Takeover 7 None 2026-01-13
North Korean Apt Lazarus Targets Developers with Malicious NPM Package 7 None 2025-01-30
Potemkin Understanding in LLMs: New Study Reveals Flaws in AI Benchmarks 7 None 2025-07-05
TC39 advances proposals for RegExp Escaping, Float16Array, Redeclarable vars 7 None 2025-02-20
Over 20,000 backdoored NPM, PyPI, and Go packages detected by Socket 7 None 2024-03-30
Deno 2.2 Improves Dependency Management and Expands Node.js Compatibility 6 None 2025-02-20
The Growing Risk of Malicious Browser Extensions 6 None 2025-06-13
Django Joins Curl in Pushing Back on AI Slop Security Reports 6 None 2025-06-30
Linux Foundation Warns Open Source Developers: Compliance with Sanctions Is Not 6 None 2025-02-07
Python 3.14 Released with Template String Literals, Deferred Annotations, and 6 None 2025-10-07
Repository Labels and Security Policies 6 None 2025-04-22
PodRocket Podcast: Inside the Recent NPM Supply Chain Attacks 6 None 2025-10-02
Obfuscation 101: Unmasking the Tricks Behind Malicious Code 6 None 2025-03-28
Tanstack NPM Packages Compromised in Ongoing Supply-Chain Attack 6 None 2026-05-11
108 Chrome Extensions Linked to Data Exfiltration and Session Theft via C2 6 None 2026-04-14
The Hidden Blast Radius of the Axios Compromise 6 None 2026-04-01
Enisa Technical Advisory on Secure Use of Package Managers 6 None 2026-03-19
React Team Updates CRA Migration Guidance After Community Pushback 6 None 2025-02-19
CISA Announces Initiative to Fortify Security of Open Source Package Registries 6 None 2024-03-07
Mobile, Alabama Hospital Refuses to Pay Settlement in Landmark Ransomware Death 5 None 2024-05-30
NPM Registry Swamped by Bizarre John Wick Frenzy 5 None 2023-03-30
CISA Rebuffs Funding Concerns as CVE Foundation Draws Criticism 5 None 2025-04-24
Trivy Supply Chain Attack Expands to Compromised Docker Images 5 None 2026-03-23
Security Community Slams MIT-Linked Report Claiming AI Powers 80% of Ransomware 5 None 2025-10-31
Axios Maintainer Confirms Social Engineering Attack Behind NPM Compromise 5 None 2026-04-03
TeamPCP Is Systematically Targeting Security Tools Across the OSS Ecosystem 5 None 2026-03-25
Lodash's Security Reset and Maintenance Reboot 5 None 2026-02-02
CISA Extends Mitre Contract as Crisis Accelerates Alternative CVE Coordination 5 None 2025-04-16
NPM targeted by malware campaign mimicking familiar library names 5 None 2025-05-02
Using Trusted Protocols Against You: Gmail as a C2 Mechanism 5 None 2025-04-30
Opengrep Adds Apex Support and New Rule Controls in Latest Updates 5 None 2025-08-12
Bun 1.2.19 Adds Isolated Installs for Better Monorepo Support 5 None 2025-07-22
Sonar to Acquire Tidelift, Scaling Open Source Maintainer Support 5 None 2024-12-18
The Unpaid Backbone of Open Source: Solo Maintainers Face Increasing Security 5 None 2024-09-23
New Axobject-Query Maintainer Faces Backlash over Controversial Decision To 5 None 2024-06-25
Researchers Uncover NPM Registry Vulnerability to Cache Poisoning and DoS 5 None 2024-06-15
Threat Actors Are Abusing GitHub's File Upload Feature to Host Malware 5 None 2024-04-23
Rubygems.org Adds New Maintainer Role 5 None 2024-11-13
Packaging Trends in Python: Highlights from the 2023 Developer Survey 5 None 2024-09-03
Uv: Python's New High-Speed Package Manager Promises to Simplify Tooling 5 None 2024-08-28
PyPI Slashes Malware Response Time: 90% of Issues Resolved in Under 24 … 5 None 2024-08-21
Node.js Takes Steps Towards Removing Corepack 5 None 2024-08-08
Ua-Parser-JS Drops MIT License, Adopts AGPLv3 and Pro Dual Licensing Model 5 None 2024-06-18
Node.js Moves Toward Stable TypeScript Support with Amaro 1.0 4 None 2025-06-11
ECMAScript 2025 Finalized with Iterator Helpers, Set Methods, RegExp.escape, and 4 None 2025-06-29
Node.js Homepage Adds Paid Support Link, Prompting Contributor Pushback 4 None 2025-06-26
Oxlint Now in Beta with 500 Built-In Rules and 2X Faster JavaScript … 4 None 2025-03-18
Vlt Launches Real-Time Dependency Analysis Powered by Socket 4 None 2025-04-17
Go Support Is Now Generally Available 4 None 2025-04-17
Bybit Hack Puts Crypto Losses at $1.6B, Surpassing All of Last Year … 4 None 2025-03-04
New PyPI Malware 'Set-Utils' Exfiltrates Ethereum Private Keys Through 4 None 2025-03-05
Malicious NPM Packages Inject SSH Backdoors via Typosquatted Libraries 4 None 2024-11-22
Stanford Study Finds 9.5% of Engineers Do Almost Nothing 4 None 2024-11-27
NIST Misses 2024 Deadline to Clear NVD Backlog 4 None 2024-10-01
Malicious Maven Package Impersonating 'XZ for Java' Library Introduces Backdoor 4 None 2024-12-06
3.7M Fake GitHub Stars: A Growing Threat Linked to Scams and Malware 4 None 2024-08-27
Supply Chain Attack on NPM Packages Injects Cryptojacking Malware 4 None 2024-12-19
PyPI on Ultralytics Supply Chain Attack: Poor CI/CD Practices to Blame, No 4 None 2024-12-14
The Business of Ransomware: Insights from Reddit AMA with Ransomware 4 None 2024-12-17
Quasar Rat Disguised as an NPM Package for Detecting Vulnerabilities in Ethereum 4 None 2024-12-20
Understanding the Risks of Trivial Packages in Modern Software Projects 4 None 2024-08-22
Gmail for Exfiltration: Malicious NPM Packages Target Solana Private Keys and 4 None 2025-01-08
Pnpm 9.5 Introduces Catalogs: Shareable Dependency Version Specifiers 4 None 2024-07-08
Opengrep Emerges as Open Source Alternative Amid Semgrep Licensing Controversy 4 None 2025-01-28
Bun 1.2 Released with 90% Node.js Compatibility and Built-In S3 Object Support 4 None 2025-01-22
OpenSSF Warns of Reputation Farming Leveraging Closed GitHub Issues and PRs 4 None 2024-06-26
Python Software Foundation Announces 5-Year Sponsorship Commitment from Fastly 4 None 2024-05-17
SSO 4 None 2024-04-30
JSR Now in Public Beta, Aims to Shift Community Towards Using ESM … 4 None 2024-03-05
Hackers are using package managers as vectors for deploying coinminer malware 4 None 2024-01-05
“Safe NPM” – NPM wrapper to protect developers from malware 4 None 2023-03-16
NPM 'bin' script confusion can override NPM/node commands 4 None 2022-10-21
NPM Registry Code Signing 4 None 2023-04-19
New Research Shows Teams of LLM Agents Can Autonomously Exploit Zero-Day 4 None 2024-06-11
The Alarming NVD Backlog: Over 50% of Known Exploited Vulnerabilities Await 4 None 2024-05-24
ESLint Is Now Language-Agnostic: Linting JSON, Markdown, and Beyond 4 None 2024-10-04
Critical Security Vulnerability in React Server Components 4 None 2025-12-04
Malicious Checkmarx Artifacts Found in Official KICS Docker Repository 4 None 2026-04-22
Ruby Gems and Go Modules Impersonate Dev Tools to Steal Secrets and … 4 None 2026-05-01
Active Supply Chain Attack Compromises Antv Packages on NPM 4 None 2026-05-19
Knip Hits 500 Releases with v5.62.0, Improving TypeScript Config Detection and 4 None 2025-07-18
Oxlint Introduces Type-Aware Linting Preview 4 None 2025-08-18
Rspack Introduces Rslint, a TypeScript-First Linter Written in Go 4 None 2025-08-20
Nx Investigation Reveals GitHub Actions Workflow Exploit Led to NPM Token Theft 4 None 2025-09-03
Rust Support Now in Beta 4 None 2025-09-11
Surveillance Malware Hidden in NPM and PyPI Packages Targets Developers With 4 None 2025-07-23
NPM Author Qix Compromised via Phishing Email 4 None 2025-09-08
Malicious Koishi Chatbot Plugin Exfiltrates Messages Triggered by 8-Character 4 None 2025-05-19
Protestware in JavaScript UI Toolkits on NPM Target Russian Language Sites 4 None 2025-06-19
Deno 2.6 and Socket: Supply Chain Defense in Your CLI 3 None 2025-12-13
Socket secures $40M to combat next-generation software supply chain attacks 3 None 2024-10-22
2023 State of JavaScript Survey Highlights: Vite Dominates, TypeScript Adoption 3 None 2024-06-23
Malicious NPM Package Exploits WhatsApp Authentication with Remote Kill Switch 3 None 2024-11-15
NPM Malware Campaign Leverages Ethereum Smart Contracts to Evade 3 None 2024-11-01
Dutch National Police Disrupt Redline and Meta Malware Operations 3 None 2024-10-29
Ruby Support in Socket 3 None 2024-10-21
Socket Optimize – CLI to override dependencies with tested, optimized versions 3 None 2024-10-16
Typosquatting on PyPI: Malicious Package Mimics Popular 'Browser-Cookie3' 3 None 2024-10-11
White House Cybersecurity Advisor Calls for Ban on Using Insurance Claims For 3 None 2024-10-08
Cloudflare Adds Security.txt Setup Wizard 3 None 2024-09-30
Malicious "express-dompurify" NPM Package Steals Browser and Cryptocurrency 3 None 2024-09-27
Enisa 2024 Threat Landscape Report Warns of Increasing State-Sponsored Supply 3 None 2024-09-27
Highlights from the 2024 Rails Community Survey 3 None 2024-09-25
Combatting Alert Fatigue by Prioritizing Malicious Intent 3 None 2024-09-23
Understanding License Exceptions: What Developers Need to Know 3 None 2024-09-20
Developer Accuses Tencent of Copyright Violation After Python Utility's License 3 None 2024-09-18
The Socket Python SDK 3 None 2024-09-13
Python Software Foundation Expands CNA Scope to Include Pallets Projects 3 None 2024-09-09
Developers Burned by Elasticsearch's License Change Aren't Going Back, Despite 3 None 2024-09-06
Socket Protects Against Revival Hijacking Attacks on PyPI 3 None 2024-09-06
Dashboard Analytics 3 None 2024-09-05
OpenSSF 75% of New Developers Lack Secure Software Skills Amid Rising 3 None 2024-09-03
Malicious 'Akiraa-Wb' NPM Package Exfiltrates Files to External Services Via 3 None 2024-08-20
Node.js Doubles Security Releases with Newly Automated Process, Re-Evaluates 3 None 2024-08-17
New Socket Web Extension, Take Socket with You 3 None 2024-08-14
New Default Security Policies 3 None 2024-08-14
White House Report Highlights Persistent Challenges and Urgent Needs in Open 3 None 2024-08-13
Adoption of Trusted Publishers Growing Among Open Source Package Repositories 3 None 2024-08-06
Node-IP Maintainer Restores GitHub Repo After Archiving Due to Overblown CVE 3 None 2024-07-11
DOJ Cracks Down on Federal Contractors for Failing to Meet Cybersecurity 3 None 2024-06-19
TC39 June 2024 Meeting Roundup: 8 Proposals Advanced to Next Stages 3 None 2024-06-13
Trojan Embedded in Crytic-Compilers Python Package Targets Blockchain Utility 3 None 2024-06-05
NIST Announces Major Contract to Clear NVD Backlog by September 3 None 2024-06-04
ESLint Approves RFC to Add Support for TypeScript Config Files 3 None 2024-05-25
OSI to Lead Discussions on Navigating the Challenges of Doing Business with … 3 None 2024-04-12
Node.js TSC Confirms: No Intention to Remove NPM from Distribution 3 None 2024-03-22
NVD Halts CVE Enrichment 3 None 2024-03-19
OpenJS Launches New Collaboration to Improve Interoperability of JavaScript 3 None 2024-02-27
JSR: What We Know So Far About Deno's New JavaScript Package Registry 3 None 2024-02-24
Socket Organization Alerts: View Dependency Security Risks Across All Repos 3 None 2023-12-21
Surge in Cyberattacks Activity Against Financial Services Industry 3 None 2023-12-01
Risky Business Podcast: Why Open Source Software Needs Better Malware Tracking 3 None 2024-11-20
Malicious NPM Package Typosquats Popular TypeScript ESLint Plugin, Exfiltrates 3 None 2024-12-11
Malicious NPM Campaign Targets Ethereum Developers with Fake Hardhat Packages 3 None 2025-01-03
Weaponizing OAST: Malicious Packages Exploit NPM, PyPI, and RubyGems 3 None 2025-01-04
Fluent Assertions Faces Backlash After Abandoning Open Source Licensing 3 None 2025-01-20
PyPI's New Archival Feature Closes a Major Security Gap 3 None 2025-01-30
Node.js EOL Versions CVE Dubbed the Worst CVE of the Year by … 3 None 2025-01-24
Malicious PyPI Package 'Pycord-Self' Targets Discord Developers with Token Theft 3 None 2025-01-16
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy 3 None 2025-02-26
Create React App Officially Deprecated Amid React 19 Compatibility Issues 3 None 2025-02-11
Maven Central Adds Sigstore Signature Validation 3 None 2025-02-06
Tick Tock, Your Credentials Are Gone: The Maven Package with a Monthly … 3 None 2025-03-14
The Pair Program Podcast: Feross Aboukhadijeh on Preserving Trust in Open Source 3 None 2025-03-10
OpenSSF Launches Open Source Project Security Baseline to Strengthen Software 3 None 2025-02-28
A New Overview in Our Dashboard 3 None 2025-04-29
Module Reachability: Focus on the Vulnerabilities That Matter 3 None 2025-04-23
The Bad Seeds: Malicious NPM and PyPI Packages Pose as Developer Tools … 3 None 2025-04-22
Malicious NPM Package Disguised as Advcash Integration Triggers Reverse Shell 3 None 2025-04-14
Malicious PyPI Package Targets WooCommerce Stores with Automated Carding Attacks 3 None 2025-04-03
OpenGrep Restores Fingerprinting in JSON and Sarif Outputs 3 None 2025-03-31
NVD Concedes Inability to Keep Pace with Surging CVE Disclosures in 2025 3 None 2025-03-28
GitHub Actions Supply Chain Attack Puts Projects at Risk 3 None 2025-03-17
Backdooring the IDE: Malicious NPM Packages Hijack Cursor Editor on macOS 3 None 2025-05-10
Malicious NPM Packages Use Telegram to Exfiltrate BullX Credentials 3 None 2025-05-08
Malicious 'Checker' Packages on PyPI Probe TikTok and Instagram for Valid 3 None 2025-05-15
Malicious Python Package Typosquats Popular Passlib Library, Shuts Down Windows 3 None 2025-06-24
Pnpm 10.12 Introduces Global Virtual Store and Expanded Version Catalogs 3 None 2025-06-11
Malicious Ruby Gems Exfiltrate Telegram Tokens, Messages Following Vietnam Ban 3 None 2025-06-03
Malicious NPM Package Wipes Codebases with Remote Trigger 3 None 2025-05-30
Malicious NPM Packages 3 None 2025-05-26
Crates.io Implements Trusted Publishing Support 3 None 2025-07-16
Socket at Black Hat and DEF Con 2025 in Las Vegas 3 None 2025-07-13
Browserslist-Rs Gets Major Refactor, Cutting Binary Size by over 1MB 3 None 2025-07-04
Rv Is a New Rust-Powered Ruby Version Manager Inspired by Python's Uv 3 None 2025-09-05
Nx NPM Packages Compromised in Supply Chain Attack Weaponizing AI CLI Tools 3 None 2025-08-27
Astral Launches Pyx: A Python-Native Package Registry 3 None 2025-08-14
Identifying and Preventing Fraudulent Engineering Candidates: An Investigation 3 None 2025-09-17
Tier 1 Reachability: Precision CVE Triage for Enterprise Teams 3 None 2025-09-09
Wallet-Draining NPM Package Impersonates Nodemailer to Hijack Crypto 3 None 2025-08-29
Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials Via 3 None 2025-08-21
Malicious Ruby Gems Used in Targeted Credential Theft Campaign 3 None 2025-08-08
TC39 Advances 11 Proposals for Math Precision, Binary APIs, and More 3 None 2025-08-06
NPM Phishing Email Targets Developers with Typosquatted Domain 3 None 2025-07-27
Toptal's GitHub Organization Hijacked: 10 Malicious Packages Published 3 None 2025-07-23
Attackers Are Hunting High-Impact Node.js Maintainers with Social Engineering 3 None 2026-04-03
AI Has Taken over Open Source 3 None 2026-05-25
Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline 3 None 2026-04-11
Temporal API Ships in Chrome 144, Marking a Major Shift for JavaScript … 3 None 2026-01-16
Tailwind CSS Announces 75% Layoffs as LLMs Reshape OSS Business Models 3 None 2026-01-08
NPM Revokes Classic Tokens, as OpenJS Warns Maintainers About OIDC Gaps 3 None 2025-12-10
Shai-Hulud Strikes Again, Again. (NPM Supply Chain Attack) 3 None 2025-11-24
Ruby Core Team Assumes Stewardship of RubyGems and Bundler, Former Maintainers 3 None 2025-10-29
Package Maintainers Call for Improvements to GitHub's New NPM Security Plan 3 None 2025-10-01
Socket raises $60M Series C at $1B valuation 3 None 2026-05-21
Popular node-ipc NPM Package Infected with Credential Stealer 3 None 2026-05-15
Socket Has Acquired Secure Annex 3 None 2026-04-28
CanisterWorm: NPM Publisher Compromise Deploys Backdoor Across 29 Packages 3 None 2026-03-21
Malicious Go "Crypto" Module Steals Passwords and Deploys Rekoobe Backdoor 3 None 2026-02-26
GlassWorm Loader Hits Open VSX via Developer Account Compromise 3 None 2026-01-31
Malicious NuGet Package Typosquats Popular .NET Tracing Library to Steal Wallet 3 None 2025-12-15
Socket at Black Hat Europe and BSides London 2025 3 None 2025-11-11
Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads 3 None 2025-11-07
NPM Typosquatted Packages Deploy Multi-Stage Credential Harvester 3 None 2025-10-28
Socket Firewall Enterprise: Flexible, Configurable Protection For 3 None 2025-10-24
Socket Integrates with Bun 1.3's Security Scanner API 3 None 2025-10-10
North Korea's Contagious Interview Campaign Escalates: 338 Malicious NPM 3 None 2025-10-10
Malicious NPM Packages Host Phishing Infrastructure Targeting 135 3 None 2025-10-09
Malicious PyPI Wheels Target Bioinformatics and MCP Developers 2 None 2026-06-09
TC39 Advances Key Proposals: Deferred Import Evaluation, Error.isError(), RegExp 2 None 2024-06-12
Cyber Extortion Demands Skyrocket in 2023 While Fewer Companies Pay Ransoms 2 None 2024-06-13
Squarespace Domain Hijacks Enabled by Email Address Exploit on Migrated Accounts 2 None 2024-07-16
Understanding the Security Concerns of NPM Shrinkwrap 2 None 2024-08-09
Mitre Marks Major Milestone, Minting 400 CNAs as NVD Backlog Grows 2 None 2024-08-14
A Large-Scale Campaign to Artificially Boost Discord Server Metrics 2 None 2024-10-04
TC39 Advances 10 ECMAScript Proposals: Key Features to Watch 2 None 2024-10-09
Nightmares on NPM:How 2 Malicious Packages Facilitate Data Theft and Destruction 2 None 2024-10-10
License Enforcement in Socket 2 None 2024-10-17
Noxia: Emerging Dark Web Hosting Provider Targets Python, Node.js, Go, and Rust 2 None 2024-10-23
Socket Recognized for Second Consecutive Year on Fortune Cyber 60 List 2 None 2024-10-30
Node.js Implements Stricter Policies for Semver-Major Pull Requests Ahead Of 2 None 2024-11-08
The Changelog Podcast: Practical Steps to Stay Safe on NPM 2 None 2025-10-31
New CNAPulse Dashboard Tracks CNA Activity and Disclosure Trends 2 None 2025-10-24
GitHub Actions Scanning Support 2 None 2025-10-23
Malware Scanning for the Hugging Face Ecosystem 2 None 2025-10-21
Google's OSV Fix Just Added 500 New Advisories – All Thanks to … 2 None 2025-10-10
The Cyber Security Council Podcast: Securing Modern Applications in A 2 None 2025-01-06
New Python Packaging Proposal Aims to Solve Phantom Dependency Problem With 2 None 2025-01-07
Socket Now Supports Uv.lock Files 2 None 2025-01-09
Pnpm 10.0.0 Blocks Lifecycle Scripts by Default 2 None 2025-01-10
Kill Switch Hidden in NPM Packages Typosquatting Chalk and Chokidar 2 None 2025-01-13
Socket Joins TC54 to Help Shape the Future of SBOMs, CycloneDX, and … 2 None 2025-01-31
Outgoing Biden Administration Issues Sweeping Executive Order on AI-Driven 2 None 2025-01-22
UK Officials Consider Banning Ransomware Payments from Public Entities 2 None 2025-01-16
38% of CISOs Fear They're Not Moving Fast Enough on AI 2 None 2025-02-04
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on NPM 2 None 2024-12-12
Typosquatting Cryptographic Libraries: Malicious NPM Packages Threaten Crypto 2 None 2024-12-01
NPM Updates Search Experience with New Objective Sorting Options 2 None 2024-12-05
Input Validation Vulnerabilities Dominate MITRE's 2024 CWE Top List 2 None 2024-11-22
Socket and Seal Security Collaborate to Fix Critical NPM Overrides Bug 2 None 2025-03-12
Opengrep Launches Playground in Alpha: A Faster, More Stable Environment For 2 None 2025-03-07
Michigan TypeScript Founder Successfully Runs Doom Inside TypeScript's Type 2 None 2025-02-28
GitHub Removes Malicious Pull Requests Targeting Open Source Repositories 2 None 2024-11-13
Show HN: Protect your Python app from an OSS supply chain attack 2 None 2023-03-01
Socket now supports the Go programming language 2 None 2023-08-02
The biggest package on npm is 5.96 GB 2 None 2024-01-10
GitHub Activates Push Protection by Default After Detecting over 1M 2 None 2024-03-04
The AI Advantage: Reshaping Cybersecurity in the Age of Autonomous Threats 2 None 2024-04-25
Historical Analytics – Now in Beta 2 None 2025-04-24
Turtles, Clams, and Cyber Threat Actors: Shell Usage 2 None 2025-04-11
VulnCon 2025: NVD Scraps Industry Consortium Plan, Raising Questions About 2 None 2025-04-11
A New Design for GitHub PR Comments 2 None 2025-04-10
Safari 18.4 Ships 3 New JavaScript Features from the TC39 Pipeline 2 None 2025-04-04
The Socket Team at RSAC and BSidesSF 2025 2 None 2025-03-27
Node.js TSC Votes to Stop Distributing Corepack 2 None 2025-03-19
Black Basta's Dependency Confusion Ambitions and Ransomware in Open Source 2 None 2025-03-19
Is Running Random Code from NPM Safe? 2 None 2024-01-03
TrapDoor Crypto Stealer Supply Chain Across NPM, PyPI, and Crates.io 2 None 2026-05-27
The Supply Chain Nightmare Before Deployment 2 None 2025-12-16
Ruby Central Faces Backlash After Publishing Incident Timeline on RubyGems 2 None 2025-10-14
NPM v12 Ships with Install Scripts Off by Default, Deprecating 2FA-Bypass Tokens 2 None 2026-07-09
Supply Chain Attack Campaign PolinRider 2 None 2026-07-06
New supply chain attack on 34 packages, 100+ versions on NPM, PyPI … 2 None 2026-05-25
North Korean Contagious Interview Campaign Drops 35 New Malicious NPM Packages 2 None 2025-06-25
2025 Blockchain and Cryptocurrency Threat Malware in the Open Source 2 None 2025-06-12
NIST Under Federal Audit for NVD Processing Backlog and Delays 2 None 2025-05-27
Node.js TSC Declines to Endorse Feature Bounty Program 2 None 2025-05-15
The Landscape of Malicious Open Source Packages: 2025 Mid‑Year Threat Report 2 None 2025-05-14
Mini Shai-Hulud has crossed from NPM into PyPI 2 None 2026-05-12
SAP Cap NPM Packages Hit by Supply Chain Attack 2 None 2026-04-29
North Korea's Contagious Interview Campaign Spreads Across 5 Ecosystems 2 None 2026-04-07
Tracking Protestware Spread: 28 NPM Packages Affected by Payload Targeting 2 None 2025-07-16
Socket for GitHub 1.0 2 None 2022-06-15
Let's Make JavaScript RegExps Streamy 2 None 2023-02-17
What we learned building an NPM CLI wrapper 2 None 2023-04-11
NPM Manifest Confusion: How Socket Protects You 2 None 2023-06-27
Limitations of CVE Security Scanners: Deep Dive into 3 Supply Chain Attacks 2 None 2023-07-10
The Socket Web Extension 2 None 2023-08-01
The "Skeleton Squad" is targeting NPM 2 None 2023-12-03
Ledger Connect-Kit Supply Chain Attack Hits Decentralized Crypto Apps 2 None 2023-12-14
Blackcat Ransomware Escaltes Hostility Following FBI Release of Decryption Tool 2 None 2023-12-21
$20M Series A to Secure Open Source Software 2 None 2024-01-09
Malicious NPM Package Targeting Roblox Users for Data Theft 2 None 2024-02-06
U.S. Sanctions LockBit Ransomware Affiliates, Law Enforcement Seizes Operations 2 None 2024-02-22
Judicious JSON – Ultimate Guide to JSON 2 None 2024-03-01
Supply Chain Attack on Axios Pulls Malicious Dependency from NPM 2 None 2026-03-31
Malicious NPM Packages Use Pastebin Steganography to Deploy Credential Stealer 2 None 2026-02-27
Socket brings supply chain security to skills.sh 2 None 2026-02-19
Rust RFC Proposes a Security Tab on Crates.io for RustSec Advisories 2 None 2025-12-09
Malicious Crate Mimicking 'Finch' Exfiltrates Credentials via a Hidden 2 None 2025-12-05
November CVEs Fell 25% YoY, Driven by Slowdowns at Major CNAs 2 None 2025-12-05
Scaling Socket from Zero to 10k Organizations 2 None 2025-12-02
Webhook Events for Alert Changes 2 None 2025-11-21
Socket Certified Patches: One-Click Fixes for Vulnerable Dependencies 2 None 2025-11-18
Malicious Chrome Extension Exfiltrates Seed Phrases, Enabling Wallet Takeover 2 None 2025-11-12
How Enterprise Security Is Adapting to AI-Accelerated Threats 2 None 2025-11-05
Malicious NPM Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet 2 None 2025-09-05
Static vs. Runtime Reachability: Insights from Latio's on the Record Podcast 2 None 2025-08-13
Precomputed Reachability Analysis in Socket 2 None 2025-07-30
Socket Now Protects the Chrome Extension Ecosystem 2 None 2025-07-30
Socket MCP for Claude Desktop 2 None 2025-07-29
Alphv/BlackCat Fakes Law Enforcement Takedown to Scam Affiliates 2 None 2024-03-06
Enhanced Security Scanning with Improved AI Alert Defaults 2 None 2024-03-25
How to Use Socket to Find Out If You Were Affected by … 2 None 2024-03-31
Software Supply Chain Compromise Now the Top Threat of the Next Half … 2 None 2024-04-02
Major Open Source Foundations Form Initiative Aimed at Building CRA-Compliant 2 None 2024-04-04
Connect with Socket at RSA and BSidesSF 2024 2 None 2024-04-15
NPM Package for ReExt React Components Library Exfiltrates Git Credentials 2 None 2024-04-18
Risky Biz Podcast: How Shifts in Open Source Made It a Prime … 2 None 2024-05-01
Socket Partners with CISA to Champion 'Secure by Design' Standards 2 None 2024-05-09
CISA Launches Vulnrichment Project as NVD Backlog Hits 10k 2 None 2024-05-10
LDAPjs Open Source Project Decommissioned After Maintainer Receives Abusive 2 None 2024-05-17
SEC Cracks Down on Unreported Data Breaches with New 30-Day Disclosure 2 None 2024-05-21
New Report Warns of LLM-Enhanced Cyber Threats: Polymorphic Malware, Customer 2 None 2024-05-29
White House to Tackle Cybersecurity Regulation Fragmentation: CISOs Spend Up To 2 None 2024-06-06
Interview on the Daytona DotFiles Insider Blog 1 None 2024-02-28
Node Congress Speaker Showcase: Interview with Feross Aboukhadijeh 1 None 2024-03-08
U.S. Government Budget Proposal Seeks Major Increase to Cybersecurity Funding In 1 None 2024-03-14
NVD Remains Stalled on Enriching CVE's, Security Industry Criticizes NIST's 1 None 2024-04-03
Chinchilla Squeaks Podcast: Modern Solutions for Securing Software Supply Chains 1 None 2024-04-09
Dependency Visualization: An Interactive Way to See Dependencies At 1 None 2024-04-11
The Dark Side of Open Source 1 None 2024-04-19
Oracle Drags Its Feet in the JavaScript Trademark Dispute 1 None 2025-02-07
Socket – Finer-grained check runs, new config options, improved reliability 1 None 2022-07-27
What’s in your NPM stat counter? A love doll store–we hope not 1 None 2022-10-24
Show HN: Socket Dependency Overview – Get Clarity over Your Dependencies 1 None 2023-03-27
Why Your SCA Tool Sucks 1 None 2023-06-26
Introducing Data Exports 1 None 2026-04-24
Malicious Chrome Extensions "Phantom Shuttle" Masquerade as a VPN to Intercept 1 None 2025-12-22
Software Engineering Daily Podcast: Feross on AI, Open Source, and Supply Chain 1 None 2025-12-11
Another Round of Tea Protocol Spam Floods NPM, but It's Not a … 1 None 2025-11-14
LockBit Dubbed "Cyber Crime Unicorn" After Reports Estimate $1B+ in Stolen Funds 1 None 2024-02-27
Unify Your Security Stack with Socket Basics 1 None 2025-10-21
Python Tools Are Quickly Adopting the New pylock.toml Standard 1 None 2025-06-24
NIST Drafts New Security Framework to Tackle Emerging Risks of Generative AI 1 None 2024-05-03
AI and A16Z Podcast: Combatting Modern Supply Chain Attacks with AI 1 None 2024-05-07
Feross on Risky Business Weekly Podcast: NPM's Ongoing Supply Chain Attacks 1 None 2025-09-10
Socket at Black Hat and DEF Con 2023 1 None 2023-07-20
Go Support 1 None 2023-08-02
Cleaning up import paths in JavaScript/TS packages 1 None 2023-08-16
Open Source Maintainers Feeling the Weight of the EU's Cyber Resilience Act 1 None 2025-07-17
Recent Trends in Malicious Packages Targeting Discord 1 None 2024-05-08
2023 Ransomware Trends: Rising Ransom Payments Drive Demand for Cyber Insurance 1 None 2023-12-11
New Tea.xyz Crypto Spam Targets Open Source Projects on GitHub 1 None 2024-03-06
UnitedHealth Group Discloses Protected Health Information Compromised For 1 None 2024-04-24
Unveiling the Dangers of the “AnyDesk-Malcom” Malicious Python Package 1 None 2023-08-24
Vite+ Joins the Push to Consolidate JavaScript Tooling 1 None 2025-10-15
Rolldown drops Rust React Compiler over a 17% binary-size increase 1 None 2026-06-28
Socket Firewall 1 None 2026-06-17
Fsnotify Maintainer Dispute Sparks Supply Chain Concerns 1 None 2026-05-12
Dependency Divergence GitHub Action 1 None 2023-10-25
Using LLMs for Analysis and Explanation in Software Supply Chain Security 1 None 2023-10-26
Socket Combats Insidious Typosquatting Supply Chain Attacks 1 None 2023-11-30
Socket CLI v0.9.0 Now Available 1 None 2023-12-04
Orbit Bridge Hackers Drain $81M in Crypto Assets 1 None 2024-01-04
'Blank Grabber' Python Package Steals Info from Discord and Telegram 1 None 2024-01-09
A Short History of Protestware 1 None 2024-01-16
Protect Your Projects from the Risks of Deprecated NPM Packages 1 None 2024-02-01
Every NPM package, sorted alphabetically by name 1 None 2022-06-23
Pixi/runner – simple alternative to events and signals, emphasizing performance 1 None 2022-07-10
PyPI Fixes High-Severity Access Control Issues Found in Security Audit 1 None 2026-05-02
Namastex.ai NPM Packages Hit with TeamPCP-Style CanisterWorm Malware 1 None 2026-04-26
Open VSX Sleeper Extensions Linked to GlassWorm Show New Malware Activations 1 None 2026-04-25