Home / Companies / Socket / Hacker News

Socket on HN

22 posts with 25+ points since 2022

Filters
Since:
Posts by Month (22 total)
Hacker News Posts
Title Points Comments Date
Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised 1,233 1,019 2025-09-16
Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign 872 432 2026-04-23
Trivy under attack again: Widespread GitHub Actions tag compromise secrets 250 83 2026-03-22
NPM to implement staged publishing after turbulent shift off classic tokens 205 125 2026-01-07
The Everything NPM Package 192 151 2024-01-06
Show HN: Socket – Secure your JavaScript supply chain 133 42 2022-03-01
The push to ban ransom payments is gaining momentum 127 166 2024-05-22
Social engineering campaign targeting tech employees spreads through NPM malware 114 87 2023-07-25
Active NPM supply chain attack: Tinycolor and 40 Packages Compromised 85 36 2025-09-15
German Court Fines Security Researcher for Reporting Company's Vulnerabilities 77 34 2024-01-23
OpenJS: "XZ Utils Cyberattack Likely Not an Isolated Incident" 65 25 2024-04-17
What's Going on Inside Your Node_modules Folder? 64 33 2022-03-02
Chinese devs are storing 1000s of eBooks on GitHub and NPM 62 12 2022-11-06
Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware 62 39 2026-08-07
Unverified NPM Account Takeover Vulnerability for Sale on Dark Web Forum 53 4 2024-07-06
Prettier NPM Packages Compromised in Supply Chain Attack 45 7 2025-07-19
Namecheap Takes Down Polyfill.io Service Following Supply Chain Attack 42 9 2024-06-26
Curl Project and Go Security Teams Reject CVSS as Broken 40 10 2025-01-24
Gem.Coop – Community-Run Alternative to Rubygems.org, Led by Former Maintainers 30 3 2025-10-06
DuckDB NPM Account Compromised in Continuing Supply Chain Attack 27 1 2025-09-09
Libxml2 Maintainer Ends Embargoed Vulnerability Reports, Citing Unsustainable 27 8 2025-06-18
Automated Spam Campaign Floods GitHub/NPM with 1000s of Garbage Packages 25 4 2024-07-12