Home / Companies / Socket / Hacker News

Socket on HN

49 posts with 1+ points in 2026

Filters
Year:
Posts by Month (49 total)
Hacker News Posts
Title Points Comments Date
Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign 869 -- 2026-04-23
Trivy under attack again: Widespread GitHub Actions tag compromise secrets 229 -- 2026-03-22
NPM to implement staged publishing after turbulent shift off classic tokens 205 -- 2026-01-07
Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware 58 -- 2026-08-07
AI Agent Lands PRs in Major OSS Projects, Targets Maintainers via Cold … 16 -- 2026-02-14
Malicious Postinstall Hook Found in 700 GitHub Repos, Including Node Projects 15 -- 2026-05-23
Shai-Hulud-Style NPM Worm Hijacks CI Workflows and Poisons AI Toolchains 9 -- 2026-02-21
Laravel Lang Compromised with RCE Backdoor Across 700 Versions 9 -- 2026-05-23
Malicious Chrome Extension Steals MEXC API Keys for Account Takeover 7 -- 2026-01-13
Tanstack NPM Packages Compromised in Ongoing Supply-Chain Attack 6 -- 2026-05-11
108 Chrome Extensions Linked to Data Exfiltration and Session Theft via C2 6 -- 2026-04-14
The Hidden Blast Radius of the Axios Compromise 6 -- 2026-04-01
Enisa Technical Advisory on Secure Use of Package Managers 6 -- 2026-03-19
Trivy Supply Chain Attack Expands to Compromised Docker Images 5 -- 2026-03-23
Axios Maintainer Confirms Social Engineering Attack Behind NPM Compromise 5 -- 2026-04-03
TeamPCP Is Systematically Targeting Security Tools Across the OSS Ecosystem 5 -- 2026-03-25
Lodash's Security Reset and Maintenance Reboot 5 -- 2026-02-02
Active Supply Chain Attack Compromises Antv Packages on NPM 4 -- 2026-05-19
Ruby Gems and Go Modules Impersonate Dev Tools to Steal Secrets and … 4 -- 2026-05-01
Malicious Checkmarx Artifacts Found in Official KICS Docker Repository 4 -- 2026-04-22
Attackers Are Hunting High-Impact Node.js Maintainers with Social Engineering 3 -- 2026-04-03
AI Has Taken over Open Source 3 -- 2026-05-25
Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline 3 -- 2026-04-11
Temporal API Ships in Chrome 144, Marking a Major Shift for JavaScript … 3 -- 2026-01-16
Tailwind CSS Announces 75% Layoffs as LLMs Reshape OSS Business Models 3 -- 2026-01-08
Socket raises $60M Series C at $1B valuation 3 -- 2026-05-21
Popular node-ipc NPM Package Infected with Credential Stealer 3 -- 2026-05-15
Socket Has Acquired Secure Annex 3 -- 2026-04-28
CanisterWorm: NPM Publisher Compromise Deploys Backdoor Across 29 Packages 3 -- 2026-03-21
Malicious Go "Crypto" Module Steals Passwords and Deploys Rekoobe Backdoor 3 -- 2026-02-26
GlassWorm Loader Hits Open VSX via Developer Account Compromise 3 -- 2026-01-31
Malicious PyPI Wheels Target Bioinformatics and MCP Developers 2 -- 2026-06-09
TrapDoor Crypto Stealer Supply Chain Across NPM, PyPI, and Crates.io 2 -- 2026-05-27
NPM v12 Ships with Install Scripts Off by Default, Deprecating 2FA-Bypass Tokens 2 -- 2026-07-09
Supply Chain Attack Campaign PolinRider 2 -- 2026-07-06
New supply chain attack on 34 packages, 100+ versions on NPM, PyPI … 2 -- 2026-05-25
Mini Shai-Hulud has crossed from NPM into PyPI 2 -- 2026-05-12
SAP Cap NPM Packages Hit by Supply Chain Attack 2 -- 2026-04-29
North Korea's Contagious Interview Campaign Spreads Across 5 Ecosystems 2 -- 2026-04-07
Supply Chain Attack on Axios Pulls Malicious Dependency from NPM 2 -- 2026-03-31
Malicious NPM Packages Use Pastebin Steganography to Deploy Credential Stealer 2 -- 2026-02-27
Socket brings supply chain security to skills.sh 2 -- 2026-02-19
Rolldown drops Rust React Compiler over a 17% binary-size increase 1 -- 2026-06-28
Socket Firewall 1 -- 2026-06-17
Fsnotify Maintainer Dispute Sparks Supply Chain Concerns 1 -- 2026-05-12
PyPI Fixes High-Severity Access Control Issues Found in Security Audit 1 -- 2026-05-02
Namastex.ai NPM Packages Hit with TeamPCP-Style CanisterWorm Malware 1 -- 2026-04-26
Open VSX Sleeper Extensions Linked to GlassWorm Show New Malware Activations 1 -- 2026-04-25
Introducing Data Exports 1 -- 2026-04-24