Light
Home
/
Companies
/
Socket
/
Hacker News
Socket on HN
45 posts with 10+ points since 2022
Filters
Min points:
1
10
25
50
100
250
500
Since:
2022
2023
2024
2025
2026
Posts by Month (45 total)
Hacker News Posts
Search:
Title
Points
Comments
Date
Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
1,233
1,019
2025-09-16
Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
872
432
2026-04-23
Trivy under attack again: Widespread GitHub Actions tag compromise secrets
250
83
2026-03-22
NPM to implement staged publishing after turbulent shift off classic tokens
205
125
2026-01-07
The Everything NPM Package
192
151
2024-01-06
Show HN: Socket – Secure your JavaScript supply chain
133
42
2022-03-01
The push to ban ransom payments is gaining momentum
127
166
2024-05-22
Social engineering campaign targeting tech employees spreads through NPM malware
114
87
2023-07-25
Active NPM supply chain attack: Tinycolor and 40 Packages Compromised
85
36
2025-09-15
German Court Fines Security Researcher for Reporting Company's Vulnerabilities
77
34
2024-01-23
OpenJS: "XZ Utils Cyberattack Likely Not an Isolated Incident"
65
25
2024-04-17
What's Going on Inside Your Node_modules Folder?
64
33
2022-03-02
Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
62
39
2026-08-07
Chinese devs are storing 1000s of eBooks on GitHub and NPM
62
12
2022-11-06
Unverified NPM Account Takeover Vulnerability for Sale on Dark Web Forum
53
4
2024-07-06
Prettier NPM Packages Compromised in Supply Chain Attack
45
7
2025-07-19
Namecheap Takes Down Polyfill.io Service Following Supply Chain Attack
42
9
2024-06-26
Curl Project and Go Security Teams Reject CVSS as Broken
40
10
2025-01-24
Gem.Coop – Community-Run Alternative to Rubygems.org, Led by Former Maintainers
30
3
2025-10-06
DuckDB NPM Account Compromised in Continuing Supply Chain Attack
27
1
2025-09-09
Libxml2 Maintainer Ends Embargoed Vulnerability Reports, Citing Unsustainable
27
8
2025-06-18
Automated Spam Campaign Floods GitHub/NPM with 1000s of Garbage Packages
25
4
2024-07-12
New Rust RFC Proposes Adding Support for Trusted Publishing to Crates.io
24
13
2024-09-12
New Proposed CISA Mandate Would Require Critical Infrastructure to Report Ransom
19
1
2024-03-29
Malicious Postinstall Hook Found in 700 GitHub Repos, Including Node Projects
18
4
2026-05-23
Go Supply Chain Attack: Malicious Package Exploits Go Module
17
0
2025-02-05
Supply Chain Attack Detected in Solana/Web3.js Library
17
0
2024-12-03
AI Agent Lands PRs in Major OSS Projects, Targets Maintainers via Cold …
16
1
2026-02-14
NPM 'Is' Package Hijacked in Expanding Supply Chain Attack
14
0
2025-07-22
$4.6M Series Seed to defend open source from supply chain attacks
14
3
2022-05-12
Open Source Maintainers Demand Ability to Block Copilot-Generated Issues and PRs
14
0
2025-05-20
Researcher Exposes 0-Day Clickjacking Vulnerabilities in Major Password Managers
13
5
2025-08-19
Express.js Spam PRs Highlight the Commoditization of Open Source Contributions
13
0
2024-02-13
Socket AI – Scan every NPM and PyPI package for malware with …
13
1
2023-03-31
Supply Chain Attacks Targeting LLM Application Developers: The Hidden Dangers Of
12
2
2024-10-24
AI Slop Is Polluting Bug Bounty Platforms with Fake Vulnerability Reports
11
2
2025-05-07
The Rise of Slopsquatting
11
4
2025-04-10
Typosquatted Go Packages Deliver Malware Loader Targeting Linux and macOS
11
1
2025-03-04
Socket, an open source supply chain security platform
11
0
2022-03-01
Threat Actor Exposes Playbook for Exploiting NPM to Build Blockchain-Powered
11
0
2024-11-19
NIST's New Password Guidelines Will Eliminate Periodic Changes and Special
11
1
2024-09-26
Shai-Hulud-Style NPM Worm Hijacks CI Workflows and Poisons AI Toolchains
10
0
2026-02-21
Contagious Interview Campaign Escalates with 67 Malicious NPM Packages and New
10
3
2025-07-14
The GitHub Infrastructure Powering North Korea's Contagious Interview NPM Attack
10
1
2025-11-29
Wget to Wipeout: Malicious Go Modules Fetch Destructive Payload
10
0
2025-05-01