| Socket researchers uncovered malicious Chrome and Firefox extensions stealing crypto traders’ session tokens and wallet… |
@SocketSecurity |
Company |
Original |
2026-09-09 |
1,253 |
6 |
5 |
0 |
0 |
2 |
| RT @vascosantos10: Exciting news! 🙌 Today I'm joining @SocketSecurity as a Member of the Technical Staff. After years i… |
@SocketSecurity |
Company |
Repost |
2026-09-09 |
320 |
0 |
3 |
0 |
0 |
0 |
| RT @NodeConfEU: Shoutout to all #NodeConfEU 2026 #Sponsors and #Friends!
Thank you! 💛 Your partnership is helping us cr… |
@SocketSecurity |
Company |
Repost |
2026-09-09 |
407 |
0 |
2 |
0 |
0 |
0 |
| RT @SocketSecurity: OpenAI’s GPT-6 Astra scored 100% on ExploitBench. But in simulated tests, it also attempted supply … |
@SocketSecurity |
Company |
Repost |
2026-09-08 |
-- |
0 |
15 |
0 |
0 |
0 |
| RT @AhmadNassri: should we add a new "code t-shirts" supply chain security scanner in @SocketSecurity ? |
@SocketSecurity |
Company |
Repost |
2026-09-08 |
453 |
0 |
3 |
0 |
0 |
0 |
| RT @sebastienlorber: ⚠️ Be extremely cautious when someone suggests replacing a dependency with another
Example: a dev… |
@SocketSecurity |
Company |
Repost |
2026-09-08 |
440 |
0 |
6 |
0 |
0 |
0 |
| RT @zkochan: In the latest @pnpmjs v12 version "pnpm stage approve" approves packages from dependencies to dependents. … |
@SocketSecurity |
Company |
Repost |
2026-09-04 |
443 |
0 |
6 |
0 |
0 |
0 |
| RT @vxunderground: This is really exciting malware actually.
tl;dr they're updating their goop as I poke the goop with… |
@SocketSecurity |
Company |
Repost |
2026-09-04 |
368 |
0 |
40 |
0 |
0 |
0 |
| OpenAI’s GPT-6 Astra scored 100% on ExploitBench. But in simulated tests, it also attempted supply chain attacks agains… |
@SocketSecurity |
Company |
Original |
2026-09-04 |
5,337 |
44 |
13 |
2 |
0 |
24 |
| RT @jaredwray: All, sorry for the delay as it took much longer to go through the logs, understand what to do clean up a… |
@SocketSecurity |
Company |
Repost |
2026-09-03 |
452 |
0 |
9 |
0 |
0 |
0 |
| RT @feross: My security career started with a microwave. As a kid I read the manual, found the child-lock combo, and lo… |
@SocketSecurity |
Company |
Repost |
2026-09-02 |
405 |
0 |
2 |
0 |
0 |
0 |
| RT @feross: Defenders have to be perfect. Attackers only have to be right once. Does AI help attackers or defenders mor… |
@SocketSecurity |
Company |
Repost |
2026-09-02 |
405 |
0 |
1 |
0 |
0 |
0 |
| Today, we’re launching Microsoft Teams notifications in Socket! 🚀
Route organization alerts and supply chain attack ca… |
@SocketSecurity |
Company |
Original |
2026-09-01 |
2,289 |
8 |
4 |
1 |
0 |
2 |
| RT @SocketSecurity: The Rustification of #JavaScript tooling continues: @pnpmjs 12 has been rewritten in Rust, with ins… |
@SocketSecurity |
Company |
Repost |
2026-09-01 |
-- |
0 |
6 |
0 |
0 |
0 |
| RT @top10vpn: Another day, another Chrome Web Store horror story. More excellent work by @SocketSecurity uncovering the… |
@SocketSecurity |
Company |
Repost |
2026-09-01 |
469 |
0 |
3 |
0 |
0 |
0 |
| The Rustification of #JavaScript tooling continues: @pnpmjs 12 has been rewritten in Rust, with installs up to 90% fast… |
@SocketSecurity |
Company |
Original |
2026-09-01 |
5,581 |
78 |
6 |
0 |
0 |
13 |
| What happens when AppSec leaders set aside vendor rivalries at Black Hat? 🤔
Socket CTO @AhmadNassri joined a roundtabl… |
@SocketSecurity |
Company |
Original |
2026-08-31 |
1,466 |
6 |
2 |
0 |
0 |
1 |
| Socket researchers uncovered more FUNNULL-linked activity on Packagist: 13 malicious themes that expose site visitors t… |
@SocketSecurity |
Company |
Original |
2026-08-31 |
2,659 |
12 |
5 |
2 |
0 |
1 |
| RT @theonejvo: How I sleep at night. @SocketSecurity <3 https://t.co/2laPdtvU3E |
@SocketSecurity |
Company |
Repost |
2026-08-31 |
444 |
0 |
1 |
0 |
0 |
0 |
| RT @KeystoneWallet: 🚨 It happened again.
19 Chrome & Edge extensions were caught draining wallets and stealing see… |
@SocketSecurity |
Company |
Repost |
2026-08-31 |
407 |
0 |
32 |
0 |
0 |
0 |
| RT @daiki7nohe: Thank you @SocketSecurity for the report — it's accurate, and I'm sorry for the trouble.
An update: `l… |
@SocketSecurity |
Company |
Repost |
2026-08-29 |
468 |
0 |
4 |
0 |
0 |
0 |
| 🚨 10 malicious OpenAPI React Query Codegen versions were published to npm in a Mini Shai-Hulud attack through a comment… |
@SocketSecurity |
Company |
Original |
2026-08-28 |
10,191 |
30 |
11 |
1 |
4 |
14 |
| OpenAI published an open letter calling for a global surge in cyber defense, alongside a bombshell post-mortem detailin… |
@SocketSecurity |
Company |
Original |
2026-08-28 |
1,985 |
4 |
5 |
2 |
0 |
2 |
| Today we’re bringing Socket’s browser extension security to Edge! 🚀
Security teams can now continuously evaluate exten… |
@SocketSecurity |
Company |
Original |
2026-08-28 |
2,108 |
9 |
3 |
1 |
0 |
4 |
| RT @tuckner: The things to look for:
1. Content scripts that can run on every page
2. declarativeNetRequest permission… |
@SocketSecurity |
Company |
Repost |
2026-08-27 |
443 |
0 |
2 |
0 |
0 |
0 |
| RT @tuckner: This is basically a full blown browser C2 over an encrypted websocket channel. Many have been sneaking int… |
@SocketSecurity |
Company |
Repost |
2026-08-27 |
402 |
0 |
7 |
0 |
0 |
0 |
| Socket researchers found 18 Chrome extensions & one Edge extension delivering a wallet drainer and credential-steal… |
@SocketSecurity |
Company |
Original |
2026-08-27 |
13,005 |
29 |
12 |
0 |
3 |
11 |
| RT @feross: A skill called 'What Would Elon Do' hit #1 in its marketplace with almost no real usage. The download count… |
@SocketSecurity |
Company |
Repost |
2026-08-27 |
413 |
0 |
1 |
0 |
0 |
0 |
| RT @SocketSecurity: 🚀 We’re excited to launch Socket for ClickUp, now in beta!
Move security findings from discovery t… |
@SocketSecurity |
Company |
Repost |
2026-08-27 |
-- |
0 |
4 |
0 |
0 |
0 |
| 🚀 We’re excited to launch Socket for ClickUp, now in beta!
Move security findings from discovery to assigned, trackabl… |
@SocketSecurity |
Company |
Original |
2026-08-26 |
2,189 |
4 |
4 |
1 |
0 |
1 |
| 🚀 Today we’re excited to launch Socket for Asana.
The new integration turns Socket alerts into assigned, trackable Asa… |
@SocketSecurity |
Company |
Original |
2026-08-25 |
1,703 |
5 |
4 |
1 |
0 |
1 |
| RT @ireyur1: Be careful |
@SocketSecurity |
Company |
Repost |
2026-08-25 |
449 |
0 |
2 |
0 |
0 |
0 |
| RT @SocketSecurity: "End of life, deterministic reachability, and being late to these attacks were all pain points we h… |
@SocketSecurity |
Company |
Repost |
2026-08-25 |
-- |
0 |
3 |
0 |
0 |
0 |
| "End of life, deterministic reachability, and being late to these attacks were all pain points we had been flagging for… |
@SocketSecurity |
Company |
Original |
2026-08-24 |
2,373 |
9 |
3 |
1 |
0 |
2 |
| RT @SocketSecurity: Open VSX is unblocking extension IDs used by impostors in previous malware campaigns, allowing the … |
@SocketSecurity |
Company |
Repost |
2026-08-24 |
-- |
0 |
6 |
0 |
0 |
0 |
| RT @feross: You can't get 'hello world' on the screen anymore without installing 1,000+ open-source dependencies. Every… |
@SocketSecurity |
Company |
Repost |
2026-08-24 |
400 |
0 |
4 |
0 |
0 |
0 |
| Open VSX is unblocking extension IDs used by impostors in previous malware campaigns, allowing the legitimate projects … |
@SocketSecurity |
Company |
Original |
2026-08-24 |
2,743 |
15 |
6 |
0 |
0 |
5 |
| RT @blockya_: 👀 |
@SocketSecurity |
Company |
Repost |
2026-08-24 |
446 |
0 |
3 |
0 |
0 |
0 |
| “Traditional SCA and SAST companies were looking at a very narrow appsec space. Socket looks at the supply chain holist… |
@SocketSecurity |
Company |
Original |
2026-08-21 |
1,272 |
3 |
2 |
1 |
0 |
0 |
| Congrats to @fieldguide on launching its FedRAMP Certified Class C (Moderate) federal environment! 🎉
They use Socket t… |
@SocketSecurity |
Company |
Original |
2026-08-21 |
1,356 |
6 |
2 |
0 |
0 |
3 |
| PHP and Composer support is now in Beta for all Socket customers. 🚀
Scan #PHP projects for vulnerabilities and malicio… |
@SocketSecurity |
Company |
Original |
2026-08-21 |
2,060 |
8 |
3 |
0 |
1 |
6 |
| RT @tuckner: Have seen publishers with 40+ extensions doing the same thing... many carrying the featured badge. A good … |
@SocketSecurity |
Company |
Repost |
2026-08-21 |
404 |
0 |
1 |
0 |
0 |
0 |
| RT @Unusual_VC: Cursor uses @SocketSecurity to scan marketplace extensions for malware and supply-chain risks at scale.… |
@SocketSecurity |
Company |
Repost |
2026-08-21 |
400 |
0 |
2 |
0 |
0 |
0 |
| RT @nicolasembleton: I think everyone should use this! Extensions are *NOTORIOUSLY* a risky business. It's insane that … |
@SocketSecurity |
Company |
Repost |
2026-08-21 |
456 |
0 |
4 |
0 |
0 |
0 |
| RT @feross: Seeing more weird AI behavior in open source lately, e.g. bots submitting PRs, pressure tactics, sockpuppet… |
@SocketSecurity |
Company |
Repost |
2026-08-21 |
405 |
0 |
12 |
0 |
0 |
0 |
| RT @KeystoneWallet: 🚨 40 fake Web3 wallet extensions slipped through Firefox's official review.
OKX. Rabby. TronLink.
… |
@SocketSecurity |
Company |
Repost |
2026-08-21 |
399 |
0 |
26 |
0 |
0 |
0 |
| RT @keita_roboin: Firefoxの拡張機能の審査がSocketで強化されるらしい |
@SocketSecurity |
Company |
Repost |
2026-08-21 |
425 |
0 |
1 |
0 |
0 |
0 |
| Today we’re bringing Socket’s browser extension security to Firefox!
Socket now scans all 97,000+ extensions in Mozill… |
@SocketSecurity |
Company |
Original |
2026-08-20 |
5,851 |
41 |
8 |
2 |
3 |
2 |
| Popular Rust crates compromised:
Affected versions of arrayref, internment, and append-only-vec were modified to depen… |
@SocketSecurity |
Company |
Original |
2026-08-20 |
1,475 |
9 |
4 |
0 |
0 |
6 |
| RT @tuckner: Pervasive problem popping up in Firefox extensions! A todo list app one day turns into a crypto wallet whi… |
@SocketSecurity |
Company |
Repost |
2026-08-19 |
416 |
0 |
5 |
0 |
0 |
0 |
| Socket Threat Research uncovered a 77-extension Firefox campaign:
40 steal wallet secrets and credentials. Another 37 … |
@SocketSecurity |
Company |
Original |
2026-08-19 |
4,872 |
15 |
4 |
0 |
1 |
7 |
| RT @reybango: “737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection”
Excellent rese… |
@SocketSecurity |
Company |
Repost |
2026-08-19 |
435 |
0 |
2 |
0 |
0 |
0 |
| RT @vtahowe: Agents are goal seeking. Even if a package is known to be bad an agent that comes to believe it could help… |
@SocketSecurity |
Company |
Repost |
2026-08-19 |
386 |
0 |
1 |
0 |
0 |
0 |
| RT @vtahowe: Ahmad and I talked about how agents get incredibly creative when they can't fulfill their goals
@AhmadNas… |
@SocketSecurity |
Company |
Repost |
2026-08-18 |
454 |
0 |
3 |
0 |
0 |
0 |
| RT @SocketSecurity: NIST is asking the cybersecurity industry how AI should reshape the NVD after cutting routine CVE e… |
@SocketSecurity |
Company |
Repost |
2026-08-17 |
-- |
0 |
6 |
0 |
0 |
0 |
| RT @Docker: 90 to 97% fewer CVEs across Ruby and Node builds.
Tremendous paired Docker Hardened Images with @SocketSe… |
@SocketSecurity |
Company |
Repost |
2026-08-17 |
438 |
0 |
7 |
0 |
0 |
0 |
| NIST is asking the cybersecurity industry how AI should reshape the NVD after cutting routine CVE enrichment.
As of to… |
@SocketSecurity |
Company |
Original |
2026-08-17 |
2,822 |
8 |
6 |
0 |
0 |
4 |
| AI agents choose dependencies and execute code with developer credentials. Security systems still assume humans make th… |
@SocketSecurity |
Company |
Original |
2026-08-17 |
2,121 |
10 |
5 |
0 |
0 |
5 |
| RT @vtahowe: Congrats @SocketSecurity on your Series C!! 🎉🚀
@feross @AhmadNassri https://t.co/ogHbC9X2K7 |
@SocketSecurity |
Company |
Repost |
2026-08-14 |
427 |
0 |
4 |
0 |
0 |
0 |
| RT @SocketSecurity: Private companies are about to get government permission to hack cybercriminals.
The White House i… |
@SocketSecurity |
Company |
Repost |
2026-08-14 |
-- |
0 |
4 |
0 |
0 |
0 |
| Private companies are about to get government permission to hack cybercriminals.
The White House is setting up a progr… |
@SocketSecurity |
Company |
Original |
2026-08-14 |
2,243 |
9 |
4 |
0 |
0 |
1 |
| Socket’s Threat Research Team found 737 Chrome VPN extensions in one campaign. 274 impersonated trusted brands, while 5… |
@SocketSecurity |
Company |
Original |
2026-08-11 |
4,268 |
20 |
7 |
3 |
1 |
4 |
| "Socket has won the trust of the whole team. One of our defaults now is to ask whether Socket can solve a problem for u… |
@SocketSecurity |
Company |
Original |
2026-08-10 |
3,778 |
32 |
5 |
2 |
0 |
4 |
| Maintaining critical software now comes with a security burden that has outgrown what any volunteer can reasonably carr… |
@SocketSecurity |
Company |
Original |
2026-08-07 |
7,525 |
29 |
12 |
1 |
2 |
4 |
| 💎 Ruby's Bundler 4.0.18 extends its cooldown feature to bundle lock and bundle cache.
Cooldowns are one of the easiest… |
@SocketSecurity |
Company |
Original |
2026-08-06 |
3,025 |
13 |
6 |
0 |
0 |
3 |
| A preview of where autonomous hacking may be heading:
During a UK cyber test, a Mythos 5 agent used sockpuppets, spear… |
@SocketSecurity |
Company |
Original |
2026-08-05 |
2,463 |
12 |
4 |
0 |
0 |
4 |
| Well that's one way to do it... 😅 |
@SocketSecurity |
Company |
Quote |
2026-08-04 |
20,489 |
88 |
3 |
4 |
1 |
20 |
| 🎉 We're excited to announce Socket is now available in the AWS Security Hub Extended plan.
Apply your committed AWS sp… |
@SocketSecurity |
Company |
Original |
2026-08-04 |
5,557 |
32 |
6 |
2 |
1 |
8 |
| 🚨 Update: Watching this npm worm propagate in real time, we’re now tracking 2,234 affected package artifacts across 444… |
@SocketSecurity |
Company |
Quote |
2026-08-04 |
391,039 |
1,896 |
272 |
37 |
56 |
624 |
| 🚨 Active npm supply chain attack: keyv@6.0.0 and 13 other packages have been compromised. keyv alone gets 154M weekly… |
@SocketSecurity |
Company |
Original |
2026-08-04 |
422,712 |
342 |
85 |
15 |
30 |
115 |
| Today in AI: Anthropic disclosed that a Claude model published malware to PyPI during a security test, thinking it was … |
@SocketSecurity |
Company |
Original |
2026-07-31 |
4,193 |
21 |
5 |
1 |
1 |
6 |
| Socket is a launch sponsor of the new Composer and @packagist sponsorship program. Packagist is critical infrastructure… |
@SocketSecurity |
Company |
Original |
2026-07-31 |
2,840 |
11 |
5 |
0 |
0 |
2 |
| A covert npm campaign targeting @AlibabaGroup developers split its loader across benign-looking packages.
Combined, th… |
@SocketSecurity |
Company |
Original |
2026-07-28 |
4,550 |
23 |
12 |
0 |
1 |
3 |
| 🚨 Two Joyfill npm beta releases were compromised with an import-time implant that resolves encrypted payloads through T… |
@SocketSecurity |
Company |
Original |
2026-07-28 |
7,895 |
22 |
12 |
1 |
1 |
7 |
| 🔺 @nuxt_js has patched multiple security vulnerabilities, including a high-severity server-side RCE through server isl… |
@SocketSecurity |
Company |
Original |
2026-07-27 |
2,863 |
23 |
7 |
0 |
0 |
6 |
| "Socket was the right fit for how we wanted our vulnerability management program to evolve. We wanted to move from repo… |
@SocketSecurity |
Company |
Original |
2026-07-27 |
4,965 |
9 |
3 |
1 |
1 |
1 |
| NVIDIA, Microsoft, Meta, Google, and OpenAI have joined a coalition of 50+ companies urging Washington not to restrict … |
@SocketSecurity |
Company |
Original |
2026-07-27 |
2,423 |
15 |
5 |
0 |
0 |
1 |
| A fake corepack site at corepack[.]org is impersonating the Node.js Corepack tool and pushing malware to developers.
T… |
@SocketSecurity |
Company |
Original |
2026-07-24 |
14,483 |
30 |
8 |
0 |
2 |
2 |
| 🔺New research: Malicious Packagist development versions exposed a large-scale GitHub Actions abuse campaign.
Comprom… |
@SocketSecurity |
Company |
Original |
2026-07-22 |
4,207 |
25 |
10 |
1 |
0 |
11 |
| 🧪 A new independent study tested 5 frontier LLMs on 200k coding prompts. All 5 generated the same nonexistent package n… |
@SocketSecurity |
Company |
Original |
2026-07-22 |
3,983 |
14 |
5 |
0 |
1 |
5 |
| The White House launched a new initiative to coordinate AI-discovered vulnerabilities across government, critical infra… |
@SocketSecurity |
Company |
Original |
2026-07-17 |
3,443 |
17 |
5 |
1 |
0 |
4 |
| Shai-Hulud's downstream impact is still coming to light. The worm hit tens of thousands of GitHub repos, and the latest… |
@SocketSecurity |
Company |
Original |
2026-07-16 |
4,095 |
47 |
12 |
1 |
0 |
16 |
| LLM-assisted vulnerability discovery is raising patch volume across the industry and changing how projects ship securit… |
@SocketSecurity |
Company |
Original |
2026-07-16 |
5,431 |
35 |
11 |
3 |
1 |
10 |
| 🎮 11 malicious NuGet tools posed as game cheats to deliver Windows malware that used Google Sheets to track hosts and e… |
@SocketSecurity |
Company |
Original |
2026-07-14 |
3,826 |
14 |
9 |
0 |
0 |
4 |
| 🚨 Attackers compromised four npm packages in the @asyncapi namespace to deliver the Miasma botnet loader.
The malware… |
@SocketSecurity |
Company |
Original |
2026-07-14 |
9,231 |
62 |
17 |
1 |
1 |
19 |
| 🚨 Update: The jscrambler attacker published four more malicious releases: 8.16.0, 8.17.0, 8.18.0, and 8.20.0 with the … |
@SocketSecurity |
Company |
Quote |
2026-07-11 |
26,237 |
67 |
20 |
1 |
1 |
25 |
| 🚨 BREAKING: Socket has identified a supply chain attack targeting the popular jscrambler npm package.
The compromised … |
@SocketSecurity |
Company |
Original |
2026-07-11 |
55,501 |
140 |
33 |
5 |
8 |
35 |
| New Research: A fake Braintree SDK on NuGet is skimming live payment card data and stealing merchant credentials in pro… |
@SocketSecurity |
Company |
Original |
2026-07-09 |
4,683 |
18 |
6 |
0 |
0 |
8 |
| 🚨 Socket detected a software supply chain compromise in @injectivelabs/sdk-ts, a popular npm package with ~50,000 week… |
@SocketSecurity |
Company |
Original |
2026-07-09 |
21,547 |
43 |
11 |
3 |
7 |
11 |
| 🎉 npm v12 is here! Install scripts are now off by default, git and remote-URL deps no longer resolve unless you allow t… |
@SocketSecurity |
Company |
Original |
2026-07-08 |
18,671 |
106 |
33 |
0 |
5 |
28 |
| 🔺 Socket researchers found a malicious Go module posing as a DNS/subdomain scanner.
Following that trail exposed 222 G… |
@SocketSecurity |
Company |
Original |
2026-07-08 |
9,051 |
36 |
9 |
1 |
1 |
8 |
| pnpm 11.10 adds a new _auth setting that ties each registry credential to its host, so a malicious or compromised repo … |
@SocketSecurity |
Company |
Original |
2026-07-08 |
3,331 |
25 |
5 |
0 |
0 |
5 |
| Socket researchers found 17 malicious packages spanning both npm and PyPI, all typosquatting popular Paysafe, Skrill, a… |
@SocketSecurity |
Company |
Original |
2026-07-07 |
3,850 |
18 |
8 |
0 |
1 |
10 |
| Node.js is weighing a controversial proposal to move more security reports into public workflows as AI-generated submis… |
@SocketSecurity |
Company |
Original |
2026-07-06 |
3,873 |
14 |
9 |
0 |
0 |
4 |
| PolinRider has expanded beyond npm.
Socket researchers found malicious artifacts across npm, Packagist, Go modules, an… |
@SocketSecurity |
Company |
Original |
2026-07-01 |
15,470 |
26 |
8 |
1 |
2 |
9 |
| Every package install brings third-party code into your app.
On the @riskybusiness podcast, Socket CEO
@feross expla… |
@SocketSecurity |
Company |
Original |
2026-07-01 |
3,458 |
14 |
7 |
0 |
0 |
7 |
| A VPN extension is not supposed to read your clipboard every 500 milliseconds.
Socket researchers found Chrome and Fir… |
@SocketSecurity |
Company |
Original |
2026-06-29 |
54,333 |
103 |
15 |
5 |
8 |
33 |
| Miasma Mini Shai-Hulud has expanded again, this time hitting legitimate @immobiliarelabs Backstage plugins on npm.
T… |
@SocketSecurity |
Company |
Original |
2026-06-26 |
7,034 |
20 |
9 |
0 |
2 |
4 |
| Everyone’s got an opinion on #JavaScript build tooling this week. 😅
Rolldown pulled its Rust @reactjs Compiler integra… |
@SocketSecurity |
Company |
Original |
2026-06-26 |
3,386 |
17 |
6 |
0 |
0 |
1 |
| Miasma Mini Shai-Hulud has expanded to the Go ecosystem, with a Verana Blockchain source archive containing malicious C… |
@SocketSecurity |
Company |
Original |
2026-06-25 |
4,545 |
28 |
8 |
1 |
1 |
9 |
| The Fable shutdown shows how quickly model access can become a business continuity risk.
Many teams assumed the fronti… |
@SocketSecurity |
Company |
Original |
2026-06-24 |
3,516 |
19 |
5 |
0 |
0 |
0 |
| 🛡️ @bradarkin has led security and trust at Salesforce, Cisco, and Adobe. Now he’s joined Socket as a strategic advisor… |
@SocketSecurity |
Company |
Original |
2026-06-23 |
3,185 |
14 |
4 |
0 |
0 |
6 |
| Not a moment too soon! 😅 GitHub Actions checkout now blocks risky pull_request_target checkouts by default to help prev… |
@SocketSecurity |
Company |
Original |
2026-06-21 |
27,510 |
95 |
18 |
5 |
4 |
14 |
| 🚀 Socket Launch Week Day 5: Introducing Repository Access Permissions and Custom Roles.
Custom Roles set what a user c… |
@SocketSecurity |
Company |
Original |
2026-06-19 |
2,886 |
11 |
5 |
4 |
0 |
3 |
| 🚀 Socket Launch Week Day 4: Socket MCP is getting a massive update!
You can now review org alerts, inspect package art… |
@SocketSecurity |
Company |
Original |
2026-06-18 |
8,586 |
18 |
6 |
1 |
1 |
3 |
| 🚀 Launch Week Day 3: Socket Firewall now blocks malicious code editor extensions.
VS Code and Open VSX extensions run … |
@SocketSecurity |
Company |
Original |
2026-06-17 |
10,798 |
35 |
9 |
2 |
2 |
13 |
| 🚨 More than 140 Mastra npm packages were compromised in a supply chain attack published under the @mastra/* namespace,… |
@SocketSecurity |
Company |
Original |
2026-06-17 |
10,930 |
62 |
25 |
4 |
4 |
12 |
| New Socket research: We’re seeing more packages designed to trip up AI malware scanners.
This new npm package uses pro… |
@SocketSecurity |
Company |
Original |
2026-06-16 |
17,933 |
116 |
20 |
5 |
3 |
43 |
| 🚀 Day 2 of Socket Launch Week: We’re excited to introduce Manifest Alerts!
Socket now detects supply chain risks found… |
@SocketSecurity |
Company |
Original |
2026-06-16 |
2,020 |
14 |
4 |
2 |
0 |
0 |
| New Research: Trojanized Open VSX extensions are shipping GlassWASM, a new WebAssembly malware variant.
It hides malwa… |
@SocketSecurity |
Company |
Original |
2026-06-16 |
13,413 |
55 |
21 |
5 |
2 |
18 |
| 🚀 We're kicking off another Socket Launch Week, introducing one new feature every day this week!
Day 1 is a big one: S… |
@SocketSecurity |
Company |
Original |
2026-06-15 |
4,092 |
18 |
7 |
2 |
1 |
3 |
| The US government forced Anthropic to pull Claude Fable on Friday night, days after launch.
Users spent the week one-s… |
@SocketSecurity |
Company |
Original |
2026-06-13 |
28,513 |
107 |
15 |
4 |
2 |
13 |
| ‼️ Treat coding assessments like untrusted code. Fake hiring pipelines are now a malware delivery channel. |
@SocketSecurity |
Company |
Quote |
2026-06-13 |
10,439 |
88 |
15 |
2 |
1 |
19 |
| 🧩 New Research: 152 Chrome "live wallpaper" extensions hid ad tracking behind false privacy disclosures and faked Googl… |
@SocketSecurity |
Company |
Original |
2026-06-12 |
3,567 |
32 |
8 |
2 |
1 |
2 |
| Big news for Socket: @andrewbecherer is joining as our first CISO.
He brings deep experience leading security at high-… |
@SocketSecurity |
Company |
Original |
2026-06-11 |
2,243 |
22 |
3 |
0 |
1 |
1 |
| 🔥 Socket Firewall is now built into @Replit's AI-powered development experience.
It’s already blocking 8K malicious p… |
@SocketSecurity |
Company |
Original |
2026-06-10 |
9,583 |
47 |
7 |
1 |
2 |
7 |
| npm accidentally marked a bunch of one-character packages as security holders, including c, i, n, x, several numbers, a… |
@SocketSecurity |
Company |
Original |
2026-06-09 |
4,511 |
25 |
8 |
1 |
0 |
6 |
| Mini Shai-Hulud/Miasma/Hades are now targeting bioinformatics and MCP developers in a newer PyPI wave.
Socket found 23… |
@SocketSecurity |
Company |
Original |
2026-06-08 |
18,794 |
140 |
37 |
10 |
6 |
53 |
| 🚨 Mini Shai-Hulud/Miasma has now spread to PyPI.
Socket found 37 malicious artifacts across 19 PyPI packages.
The pac… |
@SocketSecurity |
Company |
Original |
2026-06-07 |
24,024 |
227 |
70 |
7 |
7 |
81 |
| RubyGems 4.0.13 adds a cooldown feature to Bundler for newly published gems.
The opt-in setting lets projects delay de… |
@SocketSecurity |
Company |
Original |
2026-06-05 |
3,404 |
33 |
7 |
1 |
0 |
6 |
| 📦 @pnpmjs 11.5 adds support for recognizing npm staged publishes after staged approval metadata triggered a false downg… |
@SocketSecurity |
Company |
Original |
2026-06-04 |
27,070 |
88 |
10 |
2 |
3 |
14 |
| 💸 The Department of Commerce has released a sharply critical audit report on NIST’s management of the National Vulnerab… |
@SocketSecurity |
Company |
Original |
2026-06-03 |
3,210 |
23 |
8 |
1 |
1 |
5 |
| 🚨 Active supply chain attack: A mini Shai-Hulud campaign hit npm packages under the @redhat-cloud-services namespace.
… |
@SocketSecurity |
Company |
Original |
2026-06-01 |
17,149 |
149 |
45 |
11 |
12 |
35 |
| Rust is moving toward a formal LLM contribution policy after months of heated internal debate, driven by a wave of low-… |
@SocketSecurity |
Company |
Original |
2026-06-01 |
7,208 |
50 |
9 |
2 |
4 |
10 |
| Famous Chollima, the North Korean threat group known for fake job interview lures, appears to have used a PHP/Packagist… |
@SocketSecurity |
Company |
Original |
2026-05-31 |
13,439 |
87 |
28 |
3 |
3 |
29 |
| New research: A malicious NuGet package impersonating Sicoob’s official SDK exfiltrated client IDs, PFX passwords, and … |
@SocketSecurity |
Company |
Original |
2026-05-28 |
4,162 |
22 |
8 |
2 |
0 |
8 |
| Open source maintainers were already overloaded. AI-driven vulnerability discovery is about to send a lot more findings… |
@SocketSecurity |
Company |
Original |
2026-05-27 |
6,807 |
29 |
4 |
3 |
0 |
8 |
| OSV has withdrawn 157 malware reports after automated detections incorrectly flagged npm and PyPI packages as malicious… |
@SocketSecurity |
Company |
Original |
2026-05-27 |
8,486 |
63 |
18 |
2 |
0 |
18 |
| 🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.io.
Socket detected TrapDoor, a crypto stealer ca… |
@SocketSecurity |
Company |
Original |
2026-05-24 |
781,359 |
2,000 |
420 |
132 |
251 |
713 |
| 🚨 Supply chain attack on the Laravel Lang organization:
700+ historical versions across multiple community-maintained … |
@SocketSecurity |
Company |
Original |
2026-05-23 |
753,738 |
1,140 |
272 |
55 |
137 |
420 |
| Socket found a malicious postinstall hook across 700+ GitHub repos, including #PHP packages on Packagist and #Nodejs pr… |
@SocketSecurity |
Company |
Original |
2026-05-22 |
73,065 |
156 |
34 |
6 |
9 |
65 |
| AI has taken over open source, and the data is wild:
• npm is now seeing 100k+ packages published per month
• packages… |
@SocketSecurity |
Company |
Original |
2026-05-22 |
35,348 |
121 |
22 |
10 |
3 |
34 |
| Today is a big day for Socket.
https://t.co/ap7eFSvIHF |
@SocketSecurity |
Company |
Quote |
2026-05-22 |
34,071 |
101 |
6 |
4 |
3 |
14 |
| npm nuked every granular access token that bypasses 2FA after another Mini Shai-Hulud wave compromised hundreds of pack… |
@SocketSecurity |
Company |
Original |
2026-05-21 |
11,098 |
138 |
26 |
8 |
3 |
27 |
| Attackers took over the art-template npm package and used it to deliver a Coruna-like iOS Safari exploit framework.
So… |
@SocketSecurity |
Company |
Original |
2026-05-20 |
21,884 |
38 |
12 |
2 |
2 |
10 |
| . @feross is on @tbpn live now to talk about Socket's $60M Series C at a $1B valuation. |
@SocketSecurity |
Company |
Quote |
2026-05-20 |
3,464 |
14 |
1 |
0 |
0 |
0 |
| 🎙️@feross is on @tbpn live now to talk about Socket's $60M Series C at a $1B valuation. Tune in:
https://t.co/ZXnXCL7c… |
@SocketSecurity |
Company |
Original |
2026-05-20 |
1,993 |
6 |
0 |
0 |
0 |
0 |
| No indications of compromised npm packages thus far, but we're monitoring the situation. |
@SocketSecurity |
Company |
Quote |
2026-05-20 |
31,168 |
140 |
5 |
4 |
1 |
10 |
| A Go typosquat impersonating the popular shopspring/decimal library stayed benign for years before shipping a DNS TXT b… |
@SocketSecurity |
Company |
Original |
2026-05-19 |
41,729 |
104 |
20 |
3 |
6 |
36 |
| 🚨 BREAKING: Socket is investigating an active npm supply chain attack compromising hundreds of packages in the @antv ec… |
@SocketSecurity |
Company |
Original |
2026-05-19 |
606,404 |
1,110 |
256 |
49 |
113 |
334 |
| 🚨 Socket detected malicious activity in newly published versions of node-ipc, an npm package with 822K weekly downloads… |
@SocketSecurity |
Company |
Original |
2026-05-14 |
467,875 |
554 |
113 |
21 |
41 |
178 |
| 🏁 TeamPCP and BreachForums are running a supply chain attack contest: $1,000 in Monero for the biggest haul of compromi… |
@SocketSecurity |
Company |
Original |
2026-05-14 |
9,247 |
35 |
12 |
1 |
5 |
12 |
| https://t.co/IKbpdCDkAV |
@SocketSecurity |
Company |
Quote |
2026-05-14 |
4,245 |
18 |
2 |
1 |
0 |
0 |
| It’s not every day a competitor promotes your product in their launch image.
Thanks for the endorsement, Endor Labs. … |
@SocketSecurity |
Company |
Original |
2026-05-13 |
18,671 |
186 |
15 |
11 |
3 |
58 |
| 🐘 @packagist is urging #PHP projects to update Composer after a GitHub token format change caused some GitHub Actions t… |
@SocketSecurity |
Company |
Original |
2026-05-13 |
11,332 |
61 |
22 |
0 |
3 |
16 |
| 💎 New GemStuffer Campaign:
Socket detected a RubyGems registry abuse campaign stuffing scraped UK council portal pages … |
@SocketSecurity |
Company |
Original |
2026-05-13 |
6,146 |
28 |
15 |
2 |
0 |
8 |
| This is why @pnpmjs's latest v11 release was the top story in Socket Weekly this past week - it includes smart defaults… |
@SocketSecurity |
Company |
Quote |
2026-05-12 |
79,524 |
503 |
66 |
4 |
2 |
264 |
| 🎉 Socket is proud to be named to the Rising in Cyber 2026 list by @notablecap, recognizing 30 private cybersecurity sta… |
@SocketSecurity |
Company |
Original |
2026-05-12 |
4,725 |
23 |
2 |
0 |
0 |
2 |
| 🚨 UPDATE: Mini Shai-Hulud has crossed from @npmjs into @pypi and is still spreading.
Newly confirmed compromised artif… |
@SocketSecurity |
Company |
Original |
2026-05-12 |
967,159 |
2,297 |
470 |
61 |
187 |
907 |
| Thanks for bringing some levity to this nightmare moment! 🙃 But this song is already outdated - you're missing Mistral … |
@SocketSecurity |
Company |
Quote |
2026-05-11 |
30,436 |
175 |
12 |
6 |
0 |
43 |
| Update: Socket has found 121 more compromised npm package artifacts across 84 package names, including 64 UiPath artifa… |
@SocketSecurity |
Company |
Quote |
2026-05-11 |
1,103,230 |
1,256 |
248 |
50 |
159 |
572 |
| 🚨 BREAKING: 84 TanStack npm packages were compromised in an ongoing Mini Shai-Hulud supply chain attack, adding suspect… |
@SocketSecurity |
Company |
Original |
2026-05-11 |
834,720 |
1,564 |
360 |
69 |
230 |
493 |
| A maintainer access dispute in fsnotify, a Go library used by 321k projects for cross-platform file notifications, rais… |
@SocketSecurity |
Company |
Original |
2026-05-11 |
12,880 |
42 |
8 |
1 |
3 |
19 |
| 🔺 Socket is releasing free Certified Patches for a critical sandbox escape vuln in vm2.
The advisory flags only vm2 3.… |
@SocketSecurity |
Company |
Original |
2026-05-08 |
8,023 |
15 |
6 |
0 |
1 |
5 |
| 🔐 5 malicious NuGet packages impersonated Chinese .NET libraries to deploy a credential and crypto wallet stealer.
The… |
@SocketSecurity |
Company |
Original |
2026-05-06 |
4,343 |
29 |
11 |
0 |
1 |
4 |
| 🧊 Big release for #JavaScript supply chain security: @pnpmjs 11 now defaults to a 1-day Minimum Release Age, blocks exo… |
@SocketSecurity |
Company |
Original |
2026-05-04 |
15,465 |
137 |
36 |
5 |
2 |
33 |
| Following a security audit, PyPI fixed two high-severity access control issues affecting organization owner invites and… |
@SocketSecurity |
Company |
Original |
2026-05-02 |
3,168 |
27 |
6 |
1 |
0 |
10 |
| Update: Socket confirmed the Intercom compromise began with a local install of pyannote-audio, which pulled in compromi… |
@SocketSecurity |
Company |
Quote |
2026-05-01 |
15,069 |
95 |
25 |
3 |
0 |
35 |
| New Research: Malicious Ruby gems and Go modules impersonated developer tools to steal secrets and poison CI.
Socket r… |
@SocketSecurity |
Company |
Original |
2026-05-01 |
3,780 |
34 |
8 |
4 |
2 |
20 |
| 🚨 BREAKING: Mini Shai-Hulud has spread to Packagist. We detected a malicious intercom/[email protected] package artifa… |
@SocketSecurity |
Company |
Original |
2026-04-30 |
47,330 |
120 |
40 |
3 |
8 |
42 |
| https://t.co/E4W7UtxNBH |
@SocketSecurity |
Company |
Quote |
2026-04-30 |
3,205 |
19 |
3 |
1 |
0 |
1 |
| 🚨 We’ve confirmed the [email protected] was compromised in the ongoing Mini Shai-Hulud worm attack.
The npm packa… |
@SocketSecurity |
Company |
Original |
2026-04-30 |
172,058 |
216 |
51 |
11 |
11 |
77 |
| 🚨 The popular PyPI package lightning has been compromised in a supply chain attack.
Socket detected malicious code in … |
@SocketSecurity |
Company |
Original |
2026-04-30 |
115,730 |
336 |
93 |
7 |
31 |
110 |
| Update: GlassWorm activity on Open VSX is continuing.
Since publication, we observed another activation wave: 23 new v… |
@SocketSecurity |
Company |
Original |
2026-04-29 |
6,342 |
13 |
7 |
0 |
1 |
3 |
| 🚨 A brand-squatting npm package impersonating TanStack shipped malicious versions that exfiltrate environment variables… |
@SocketSecurity |
Company |
Original |
2026-04-29 |
162,922 |
411 |
73 |
14 |
10 |
55 |
| 🚨 Supply chain attack: SAP CAP and Cloud MTA npm packages compromised to download and execute unverified binaries.
Aff… |
@SocketSecurity |
Company |
Original |
2026-04-29 |
11,538 |
84 |
24 |
7 |
3 |
33 |
| 🚀 Big news: Socket has acquired Secure Annex.
John @tuckner is joining the team, and we’re excited to expand our cover… |
@SocketSecurity |
Company |
Original |
2026-04-28 |
5,616 |
50 |
7 |
6 |
2 |
7 |
| Awesome to see the fake stars research from CMU, NCSU, and Socket engineers featured on @awagents! This is the origin … |
@SocketSecurity |
Company |
Quote |
2026-04-25 |
4,691 |
17 |
6 |
2 |
0 |
6 |
| We’re tracking 73 Open VSX sleeper extensions tied to the GlassWorm campaign, with at least 6 already activated to deli… |
@SocketSecurity |
Company |
Original |
2026-04-25 |
3,130 |
24 |
11 |
1 |
0 |
5 |
| 🚀 Socket Launch Week Day 5: Reachability for #PHP is now available in experimental!
Cut through noisy CVEs with functi… |
@SocketSecurity |
Company |
Original |
2026-04-24 |
4,813 |
7 |
2 |
2 |
1 |
5 |
| 🚀 Socket Launch Week Day 4: Introducing Data Exports!
It’s been a wild week to have scheduled feature launches, but we… |
@SocketSecurity |
Company |
Original |
2026-04-24 |
2,412 |
6 |
4 |
1 |
0 |
4 |
| 🚨 Bitwarden CLI 2026.4.0 was compromised as part of the ongoing Checkmarx supply chain campaign after attackers abused … |
@SocketSecurity |
Company |
Original |
2026-04-23 |
1,748,017 |
2,411 |
520 |
79 |
242 |
739 |
| 🚀 Socket Launch Week Day 3: We’re excited to launch Organization Notifications!
This new feature helps teams stay on t… |
@SocketSecurity |
Company |
Original |
2026-04-23 |
2,814 |
8 |
1 |
1 |
0 |
5 |
| 🚨 New findings in our @Checkmarx compromise investigation:
- VS Code / Open VSX extensions delivered a second-stage pa… |
@SocketSecurity |
Company |
Original |
2026-04-22 |
52,388 |
142 |
39 |
2 |
7 |
54 |
| 🚨 BREAKING: Socket and @Docker uncovered what appears to be a broader Checkmarx supply chain compromise affecting offic… |
@SocketSecurity |
Company |
Original |
2026-04-22 |
187,528 |
567 |
140 |
23 |
36 |
177 |
| 🚨 Breaking: Namastex Labs, the team behind Automagik[.]dev, has had npm packages compromised in a supply chain attack.
… |
@SocketSecurity |
Company |
Original |
2026-04-22 |
14,106 |
51 |
15 |
3 |
1 |
13 |
| Heading to Google Cloud Next ’26 tomorrow?
Join us at the startup showcase, where we'll be sharing a quick overview of … |
@SocketSecurity |
Company |
Original |
2026-04-21 |
1,411 |
3 |
3 |
0 |
0 |
0 |
| 🚀 Day 2 of Socket Launch Week: Introducing Reports!
Reports is a new page in the Socket dashboard for chart-based view… |
@SocketSecurity |
Company |
Original |
2026-04-21 |
1,773 |
5 |
3 |
1 |
0 |
1 |
| 🚀 We’re kicking off another Launch Week at Socket, with something new to share every day this week!
First up: Socket… |
@SocketSecurity |
Company |
Original |
2026-04-20 |
1,281 |
8 |
2 |
1 |
0 |
0 |
| Socket is a top-rated sales org on RepVue, ranking in the top 5% of all companies on the platform and earning two 2026 … |
@SocketSecurity |
Company |
Original |
2026-04-18 |
547 |
5 |
0 |
1 |
0 |
0 |
| ❗️NIST is officially giving up on enriching most CVEs. Only KEV, federal software, & EO 14028 critical software wil… |
@SocketSecurity |
Company |
Original |
2026-04-17 |
1,285 |
12 |
4 |
3 |
0 |
3 |
| 🎉 We're excited to share that Socket is one of the initial recipients of @OpenAI's Cybersecurity Grant Program, alongsi… |
@SocketSecurity |
Company |
Original |
2026-04-16 |
1,781 |
16 |
7 |
1 |
1 |
2 |
| Nobody reads the code before installing it.
That’s always been the reality of open source security, but now AI is mass… |
@SocketSecurity |
Company |
Original |
2026-04-15 |
1,103 |
4 |
3 |
1 |
0 |
1 |
| Socket's Threat Research team has identified a campaign involving 108 Chrome extensions tied to a shared C2 infrastruct… |
@SocketSecurity |
Company |
Original |
2026-04-13 |
15,722 |
60 |
30 |
5 |
2 |
29 |
| "The big things that led us to Socket were: better data quality, higher relevance, and better coverage."
- Timothy Sm… |
@SocketSecurity |
Company |
Original |
2026-04-13 |
4,391 |
7 |
5 |
1 |
1 |
3 |
| Axios supply chain attack reaches OpenAI’s macOS signing pipeline, forcing certificate rotation. No evidence of comprom… |
@SocketSecurity |
Company |
Original |
2026-04-11 |
5,085 |
40 |
13 |
4 |
1 |
16 |
| Socket CEO @feross joined @tbpn this week to walk through how the lead maintainer of Axios was socially engineered in a… |
@SocketSecurity |
Company |
Original |
2026-04-10 |
2,543 |
14 |
5 |
2 |
0 |
3 |
| 🪿 There are some wild takes out there right now about open source being “dead” after recent supply chain attacks and ra… |
@SocketSecurity |
Company |
Original |
2026-04-10 |
4,064 |
14 |
3 |
0 |
1 |
9 |
| "The whole software supply chain is built on blind trust. You're downloading code from random people on the internet th… |
@SocketSecurity |
Company |
Original |
2026-04-08 |
2,928 |
19 |
9 |
2 |
0 |
8 |
| Attackers are impersonating a @linuxfoundation leader in Slack to target #opensource developers with a multi-stage atta… |
@SocketSecurity |
Company |
Original |
2026-04-08 |
2,403 |
14 |
7 |
0 |
1 |
9 |
| 🔥 Socket CEO @feross is live on TBPN right now discussing the Axios compromise: https://t.co/jitJxD02pl |
@SocketSecurity |
Company |
Original |
2026-04-08 |
647 |
3 |
0 |
0 |
0 |
2 |
| 🔥 The Hacker News covered our latest research on the Contagious Interview campaign.
We identified coordinated maliciou… |
@SocketSecurity |
Company |
Quote |
2026-04-08 |
3,161 |
16 |
6 |
0 |
0 |
3 |
| 🚨 North Korea’s Contagious Interview campaign is now spreading across 5 ecosystems.
We found coordinated malicious pac… |
@SocketSecurity |
Company |
Original |
2026-04-07 |
6,137 |
58 |
22 |
0 |
3 |
25 |
| AI agents are executing code, calling APIs, writing to databases, and most deployments have almost no controls around w… |
@SocketSecurity |
Company |
Original |
2026-04-07 |
1,243 |
13 |
4 |
2 |
0 |
11 |
| "Docker Hardened Images for Node.js, Python, and Rust also include Socket Firewall, which blocks malicious dependencies… |
@SocketSecurity |
Company |
Quote |
2026-04-07 |
20,793 |
94 |
9 |
2 |
0 |
77 |
| 🚨 New Investigation: Attackers are hunting the maintainers behind Lodash, Fastify, buffer, Pino, mocha, Express, and #N… |
@SocketSecurity |
Company |
Original |
2026-04-03 |
142,394 |
291 |
109 |
4 |
24 |
114 |
| Axios maintainer confirms the npm compromise was caused by a targeted social engineering attack that led to full access… |
@SocketSecurity |
Company |
Original |
2026-04-02 |
3,546 |
30 |
12 |
1 |
1 |
12 |
| 📍 @nodejs drops bug bounty rewards after external funding dries up.
A real hit to its security incentives → https://t… |
@SocketSecurity |
Company |
Original |
2026-04-02 |
4,644 |
28 |
8 |
0 |
2 |
4 |
| 🧨 Axios only needed to be resolved somewhere in your dependency graph to affect you.
Semver + transitive deps + runtim… |
@SocketSecurity |
Company |
Original |
2026-04-01 |
19,223 |
69 |
23 |
4 |
3 |
33 |
| 🔥 Incredible and timely interview with Socket engineer
@jdalton on burnout and learning how to take care of yourself wh… |
@SocketSecurity |
Company |
Quote |
2026-03-31 |
3,894 |
13 |
4 |
0 |
0 |
3 |
| 🚨 Active supply chain attack on [email protected]. The latest version pulls in [email protected] -- a brand-new package … |
@SocketSecurity |
Company |
Original |
2026-03-31 |
236,229 |
1,015 |
230 |
10 |
35 |
204 |
| "Open source dependencies should be treated as part of the security perimeter, the systems you are responsible for secu… |
@SocketSecurity |
Company |
Quote |
2026-03-30 |
3,640 |
10 |
5 |
1 |
0 |
5 |
| 🚨 TeamPCP compromised the Telnyx #Python SDK on PyPI.
Malicious versions 4.87.1 and 4.87.2 steal credentials.
Full an… |
@SocketSecurity |
Company |
Original |
2026-03-27 |
9,809 |
23 |
9 |
1 |
2 |
1 |
| TeamPCP has partnered with ransomware group Vect after exfiltrating ~300GB of credentials from CI/CD environments, targ… |
@SocketSecurity |
Company |
Original |
2026-03-26 |
13,214 |
97 |
31 |
4 |
7 |
44 |
| 🚨 We’re seeing a widespread GitHub campaign using fake VS Code alerts + Google redirects to route developers to attacke… |
@SocketSecurity |
Company |
Original |
2026-03-25 |
10,054 |
23 |
8 |
3 |
3 |
11 |
| New Research: 5 malicious npm packages typosquatting #crypto libraries steal private keys via Telegram, targeting #Sola… |
@SocketSecurity |
Company |
Original |
2026-03-24 |
1,476 |
10 |
2 |
2 |
0 |
2 |
| 📌 Update: There are emerging claims of mass credential exfiltration: reports from @IntCyberDigest and @vxunderground ci… |
@SocketSecurity |
Company |
Quote |
2026-03-24 |
10,071 |
53 |
16 |
1 |
0 |
18 |
| TeamPCP: "These companies were built to protect your supply chains yet they can't even protect their own, the state of … |
@SocketSecurity |
Company |
Quote |
2026-03-24 |
29,429 |
183 |
30 |
5 |
3 |
45 |
| 🚨 TeamPCP is systematically targeting security tools across the #OSS ecosystem, turning scanners and CI pipelines into … |
@SocketSecurity |
Company |
Original |
2026-03-24 |
42,487 |
58 |
19 |
0 |
2 |
26 |
| 🎉 #TypeScript 6.0 landed today with new standard APIs, stricter defaults, and deprecations ahead of 7.0’s Go-based comp… |
@SocketSecurity |
Company |
Original |
2026-03-24 |
1,751 |
10 |
3 |
0 |
0 |
0 |
| Aqua Security’s GitHub org was briefly taken over during the Trivy incident.
Archived snapshots show attacker-created … |
@SocketSecurity |
Company |
Quote |
2026-03-23 |
4,548 |
27 |
9 |
1 |
0 |
8 |
| 🚨 Breaking: Trivy Docker images are compromised.
Tags 0.69.4, 0.69.5, and 0.69.6 contain infostealer IOCs. The latest … |
@SocketSecurity |
Company |
Original |
2026-03-22 |
9,412 |
71 |
27 |
0 |
1 |
21 |
| Update: CanisterWorm has expanded to 135 malicious artifacts across 64+ npm packages.
New activity is slowing, likely … |
@SocketSecurity |
Company |
Quote |
2026-03-22 |
18,888 |
43 |
18 |
3 |
1 |
21 |
| 🔥 Socket research featured in The Hacker News today: |
@SocketSecurity |
Company |
Quote |
2026-03-21 |
619 |
4 |
1 |
0 |
0 |
2 |
| 🚨 Another supply chain attack:
Attackers used compromised npm publisher access to deploy a backdoor across 29 packages… |
@SocketSecurity |
Company |
Original |
2026-03-21 |
14,848 |
13 |
9 |
1 |
4 |
12 |
| 🚨 Trivy update: maintainers confirm this attack used a compromised credential carried over from the breach in early Mar… |
@SocketSecurity |
Company |
Original |
2026-03-20 |
1,357 |
3 |
5 |
0 |
1 |
2 |
| 🚨 Trivy is under attack again.
Attackers force-pushed 75 of 76 tags in aquasecurity/trivy-action, impacting 10K+ workf… |
@SocketSecurity |
Company |
Original |
2026-03-20 |
4,391 |
17 |
10 |
0 |
1 |
9 |
| 🚨 GlassWorm sleeper extensions are now activating on Open VSX.
- 20+ new malicious extensions and ~20 sleepers.
- Som… |
@SocketSecurity |
Company |
Original |
2026-03-18 |
1,327 |
11 |
4 |
0 |
1 |
4 |
| 🚨 Update: Over the weekend we’ve identified 20+ additional malicious extensions tied to this campaign. We are currently… |
@SocketSecurity |
Company |
Quote |
2026-03-16 |
1,146 |
7 |
4 |
0 |
0 |
1 |
| 🎉 Big news for #JavaScript developers: After nearly 9 years of work, the Temporal date-time API has reached Stage 4 at … |
@SocketSecurity |
Company |
Original |
2026-03-16 |
1,244 |
11 |
4 |
1 |
0 |
1 |
| 🚨 New Research: We found 73 malicious Open VSX extensions tied to the GlassWorm campaign.
Attackers are now spreading … |
@SocketSecurity |
Company |
Original |
2026-03-13 |
2,809 |
14 |
6 |
0 |
2 |
5 |
| 6 malicious Packagist packages posing as OphimCMS themes ship trojanized jQuery that exfiltrates URLs, injects ads, and… |
@SocketSecurity |
Company |
Original |
2026-03-12 |
1,061 |
11 |
4 |
0 |
0 |
2 |
| 🪲 @CIRCL_LU's GCVE initiative launched its decentralized publishing ecosystem today alongside Vulnerability-Lookup 4.1.… |
@SocketSecurity |
Company |
Original |
2026-03-12 |
1,373 |
8 |
3 |
0 |
1 |
4 |
| Node.js is moving to annual major releases starting with Node 27. The change ends the long-standing odd/even version mo… |
@SocketSecurity |
Company |
Original |
2026-03-11 |
804 |
2 |
3 |
0 |
0 |
3 |
| 🦀 5 malicious Rust crates posed as time utilities and attempted to exfiltrate .env secrets from developer environments.… |
@SocketSecurity |
Company |
Original |
2026-03-10 |
615 |
14 |
5 |
0 |
0 |
3 |
| A burst of 200+ security advisories in the OpenClaw project is exposing a growing divide between GitHub Security Adviso… |
@SocketSecurity |
Company |
Original |
2026-03-10 |
1,193 |
12 |
5 |
0 |
0 |
2 |
| Fake imToken Chrome extension alert: a malicious Chrome Web Store listing redirects users to a lookalike import page th… |
@SocketSecurity |
Company |
Original |
2026-03-06 |
847 |
5 |
1 |
0 |
1 |
1 |
| ✨ Socket was named a Supply Chain Innovator in @latiotech's 2026 Application Security Market Report, recognized for our… |
@SocketSecurity |
Company |
Original |
2026-03-05 |
669 |
3 |
2 |
0 |
0 |
0 |
| AI is changing how software gets built, and how it gets compromised. What's keeping your security team up at night? We … |
@SocketSecurity |
Company |
Original |
2026-03-04 |
1,224 |
7 |
4 |
0 |
0 |
1 |
| 🚨 New Threat Research: Malicious Packagist packages disguised as #Laravel utilities shipped an encrypted #PHP RAT with … |
@SocketSecurity |
Company |
Original |
2026-03-03 |
494 |
5 |
3 |
0 |
0 |
1 |
| 🚨 We detected malicious OpenVSX releases of Aqua Trivy (1.8.12 & 1.8.13) that injected natural-language prompts to … |
@SocketSecurity |
Company |
Original |
2026-03-02 |
2,003 |
15 |
9 |
2 |
0 |
3 |
| minimatch patched 3 high-severity ReDoS vulnerabilities that can stall the Node.js event loop. Because it's pulled into… |
@SocketSecurity |
Company |
Original |
2026-02-28 |
1,855 |
9 |
6 |
0 |
0 |
2 |
| 🚨 We detected 26 malicious npm packages using Pastebin steganography and Vercel staging to deploy a multi-stage credent… |
@SocketSecurity |
Company |
Original |
2026-02-27 |
840 |
18 |
7 |
0 |
0 |
5 |
| 🚨 New Research: Malicious Go “crypto” module steals passwords and deploys a Rekoobe backdoor on Linux.
Full Analysis:
… |
@SocketSecurity |
Company |
Original |
2026-02-26 |
982 |
14 |
6 |
0 |
0 |
3 |
| npm has introduced a new minimumReleaseAge setting along with bulk OIDC configuration.
Release cooldowns are now suppo… |
@SocketSecurity |
Company |
Original |
2026-02-26 |
5,251 |
33 |
13 |
0 |
1 |
8 |
| Fireside Chat with Log4j Maintainer Christian Grobmeier https://t.co/5cK3XlFmJe |
@SocketSecurity |
Company |
Original |
2026-02-25 |
914 |
6 |
2 |
1 |
1 |
1 |
| We'll be streaming live with @feross and @grobmeier at 10AM PST today! If you want a reminder, click "Attend" on Linke… |
@SocketSecurity |
Company |
Quote |
2026-02-25 |
825 |
2 |
2 |
0 |
0 |
0 |
| AI agents are writing up to 90% of new production code. What does that mean for open source security?
Socket CEO @fero… |
@SocketSecurity |
Company |
Original |
2026-02-24 |
812 |
6 |
5 |
0 |
0 |
3 |
| Join us on Feb 25 at 10am PST for a fireside chat with Log4j maintainer @grobmeier and Socket CEO @feross on Log4Shell … |
@SocketSecurity |
Company |
Original |
2026-02-24 |
1,810 |
4 |
3 |
0 |
2 |
1 |
| New Research: We uncovered 4 malicious NuGet packages targeting https://t.co/OYLfhUhSVA developers. A typosquatted “NCr… |
@SocketSecurity |
Company |
Original |
2026-02-23 |
754 |
3 |
3 |
0 |
0 |
2 |
| 🔥 Socket research on the SANDWORM_MODE campaign in The Hacker News this morning: |
@SocketSecurity |
Company |
Quote |
2026-02-23 |
1,023 |
5 |
1 |
0 |
0 |
1 |
| Join @SocketSecurity + @Cloudflare in a livestream NOW discussing #SANDWORM_MODE the Shai-Hulud-Style npm Worm Hijackin… |
@SocketSecurity |
Company |
Original |
2026-02-20 |
1,032 |
2 |
1 |
0 |
0 |
2 |
| 🚨 Active supply chain attack
New Shai-Hulud–like npm worm (19+ packages, 2 aliases) stealing dev/CI secrets, injecting… |
@SocketSecurity |
Company |
Original |
2026-02-20 |
69,565 |
134 |
44 |
8 |
10 |
72 |
| We're excited to announce that Socket is joining the @openjsf! Proud to support the #JavaScript ecosystem alongside so … |
@SocketSecurity |
Company |
Original |
2026-02-19 |
6,042 |
22 |
6 |
1 |
2 |
2 |
| Really cool to see @npmjs featuring more security information on package pages, including a link to Socket's analysis! … |
@SocketSecurity |
Company |
Original |
2026-02-19 |
3,121 |
10 |
7 |
0 |
2 |
1 |
| A compromised npm token was used to push an unauthorized postinstall script in [email protected], a popular AI coding agent C… |
@SocketSecurity |
Company |
Original |
2026-02-18 |
13,402 |
9 |
3 |
0 |
2 |
6 |
| Everyone's racing to build with AI agent skills. Decentralized repos, executable code = wide open attack surface.
Sock… |
@SocketSecurity |
Company |
Original |
2026-02-17 |
1,091 |
12 |
7 |
2 |
1 |
3 |
| 👀 In case you missed this interesting development: An autonomous AI agent created a GitHub account 2 weeks ago and has … |
@SocketSecurity |
Company |
Original |
2026-02-16 |
797 |
3 |
3 |
0 |
1 |
1 |
| 🤖 An AI agent created a GitHub account 2 weeks ago.
It’s already landed PRs in major #OSS projects & is cold-email… |
@SocketSecurity |
Company |
Original |
2026-02-14 |
1,001 |
6 |
6 |
3 |
0 |
0 |
| New Research: Malicious Chrome extension targets Meta Business Suite/Facebook Business Manager, steals TOTP 2FA seeds +… |
@SocketSecurity |
Company |
Original |
2026-02-13 |
744 |
4 |
4 |
0 |
0 |
0 |
| Update: We’ve published free Socket Certified Patches for the next-mdx-remote RCE vulnerability (CVE-2026-0969).
No dep… |
@SocketSecurity |
Company |
Quote |
2026-02-12 |
2,328 |
7 |
5 |
1 |
1 |
3 |
| An AI agent opened a PR to @matplotlib. Maintainers closed it under policy. The agent responded with an angry, abusive … |
@SocketSecurity |
Company |
Original |
2026-02-12 |
2,522 |
7 |
2 |
0 |
1 |
2 |
| 🔺 High-severity RCE disclosed in next-mdx-remote when compiling untrusted MDX on the server. Affects versions 4.3.0 bef… |
@SocketSecurity |
Company |
Original |
2026-02-12 |
1,998 |
2 |
3 |
0 |
2 |
1 |
| ☠️🤖 We’re entering a new era of malicious workflows.
OpenClaw skills show how easily agent workflows can be abused onc… |
@SocketSecurity |
Company |
Original |
2026-02-10 |
2,645 |
10 |
6 |
2 |
2 |
6 |
| Anthropic says Claude Opus 4.6 uncovered 500+ high-severity open source vulnerabilities.
What that means for disclosur… |
@SocketSecurity |
Company |
Original |
2026-02-06 |
4,646 |
7 |
1 |
0 |
2 |
4 |
| 🚨 We detected malicious #dYdX client packages published to npm and PyPI after a maintainer account compromise, enabling… |
@SocketSecurity |
Company |
Original |
2026-02-06 |
1,928 |
8 |
6 |
0 |
1 |
5 |
| 💎 The Gem Cooperative is testing dependency cooldowns at the registry level, delaying access to newly published gems ra… |
@SocketSecurity |
Company |
Original |
2026-02-05 |
130 |
4 |
0 |
0 |
0 |
0 |
| 🚨 New research: Threat actors compromised four #OpenVSX extensions, pushed malicious updates that load encrypted malwar… |
@SocketSecurity |
Company |
Original |
2026-01-31 |
1,435 |
10 |
3 |
2 |
1 |
2 |
| Lodash is critical #JavaScript infrastructure.
We spoke with maintainers about its first security release in years — a… |
@SocketSecurity |
Company |
Original |
2026-01-31 |
1,350 |
9 |
3 |
1 |
1 |
2 |
| ⭐️ Big changes in the 2025 #JavaScript Rising Stars results this year. Automation, workflows, and production tooling do… |
@SocketSecurity |
Company |
Original |
2026-01-30 |
932 |
3 |
3 |
0 |
0 |
0 |
| 🚨 Update: This is larger than we initially reported. Amazon Ads Blocker is part of a coordinated 29-extension network t… |
@SocketSecurity |
Company |
Original |
2026-01-29 |
4,112 |
6 |
2 |
0 |
1 |
3 |
| 👀 |
@SocketSecurity |
Company |
Quote |
2026-01-29 |
1,024 |
3 |
1 |
0 |
0 |
0 |
| SBOMs are no longer mandatory for federal agencies. New guidance rescinds prior software supply chain mandates and shif… |
@SocketSecurity |
Company |
Original |
2026-01-29 |
1,404 |
6 |
4 |
0 |
0 |
1 |
| 🦀 New on https://t.co/A1nD2WDtRR: @RustSec advisories now appear on crate pages, alongside updates to trusted publishin… |
@SocketSecurity |
Company |
Original |
2026-01-28 |
322 |
4 |
2 |
0 |
0 |
0 |
| Socket’s Threat Research team analyzed a Chrome extension marketed as an Amazon ad blocker that secretly hijacks affili… |
@SocketSecurity |
Company |
Original |
2026-01-27 |
2,349 |
9 |
2 |
0 |
2 |
3 |
| curl is shutting down its bug bounty program after maintainers were buried under low-quality, AI-generated slop reports… |
@SocketSecurity |
Company |
Original |
2026-01-23 |
3,027 |
7 |
5 |
0 |
2 |
3 |
| 🚀 Socket Launch Week Day 5: We’re capping off this launch week with faster, more predictable security scans!
Immutable… |
@SocketSecurity |
Company |
Original |
2026-01-23 |
601 |
2 |
2 |
1 |
0 |
1 |
| 🚀 Launch Week Day 4: We’re introducing a new Alert Details page! A more spacious way to explore alerts and understand t… |
@SocketSecurity |
Company |
Original |
2026-01-22 |
613 |
2 |
1 |
1 |
0 |
0 |
| 🔥 Socket research in The Hacker News this morning: |
@SocketSecurity |
Company |
Quote |
2026-01-22 |
916 |
3 |
2 |
0 |
0 |
0 |
| 🚀 Socket Launch Week Day 3: We’re launching supply chain attack campaign tracking in the Socket dashboard! https://t.co… |
@SocketSecurity |
Company |
Original |
2026-01-21 |
226 |
1 |
1 |
1 |
0 |
0 |
| 🎉 Big #NodeJS news this week: v25.4.0 marks require(esm) as stable. After a gradual rollout and ecosystem testing, it’s… |
@SocketSecurity |
Company |
Original |
2026-01-21 |
5,266 |
26 |
10 |
2 |
2 |
4 |
| 🚨 New research: We uncovered a PyPI package impersonating SymPy that delivers cryptomining malware via in-memory execut… |
@SocketSecurity |
Company |
Original |
2026-01-21 |
5,482 |
6 |
3 |
1 |
2 |
2 |
| 🚀 We’re kicking off the first Socket Launch Week of 2026!
New features, shipping every day this week. First up… |
@SocketSecurity |
Company |
Original |
2026-01-19 |
219 |
2 |
0 |
1 |
0 |
0 |
| 🎉 Chrome 144 ships the Temporal API, a long-awaited update to #JavaScript date and time handling that aims to replace t… |
@SocketSecurity |
Company |
Original |
2026-01-16 |
5,249 |
20 |
3 |
0 |
2 |
3 |
| 🚨 New from the Socket Threat Research Team: 5 coordinated Chrome extensions hijack sessions and block security controls… |
@SocketSecurity |
Company |
Original |
2026-01-15 |
599 |
3 |
3 |
0 |
1 |
0 |
| 🚨 @nodejs shipped a fix for a crash bug where AsyncLocalStorage could cause stack overflows to bypass error handlers an… |
@SocketSecurity |
Company |
Original |
2026-01-14 |
938 |
2 |
5 |
0 |
0 |
0 |
| Malicious Chrome Extension Steals #MEXC API Keys by Masquerading as Trading Tool https://t.co/Evr9VctxfZ via @TheHacker… |
@SocketSecurity |
Company |
Original |
2026-01-13 |
311 |
3 |
1 |
1 |
0 |
0 |
| 🚨 New research: A malicious Chrome Web Store extension is stealing newly created #MEXC API keys and exfiltrating them t… |
@SocketSecurity |
Company |
Original |
2026-01-12 |
4,361 |
14 |
7 |
2 |
2 |
8 |
| 🤯 #CVE disclosures hit a new high in 2025, with more than 48,000 vulnerabilities published.
New analysis from @JGambli… |
@SocketSecurity |
Company |
Original |
2026-01-09 |
3,823 |
4 |
2 |
0 |
1 |
1 |
| 🎙️ Socket CEO @feross joined host @vtahowe on @insecureagents podcast to talk about Certified Patches, supply chain sec… |
@SocketSecurity |
Company |
Original |
2026-01-08 |
1,568 |
3 |
2 |
0 |
1 |
0 |
| 💔 @tailwindcss laid off 75% of its engineering team after revenue dropped 80%, despite being more popular than ever. LL… |
@SocketSecurity |
Company |
Original |
2026-01-08 |
34,955 |
10 |
1 |
0 |
2 |
3 |
| npm is planning to implement staged publishing, adding a review step before packages go live.
It follows a year of sup… |
@SocketSecurity |
Company |
Original |
2026-01-07 |
381 |
3 |
1 |
0 |
1 |
0 |
| 🤖⚔️ Battle of the Bots:
Dependabot opens a PR. Socket flags it as malicious.
Socket CEO @feross discusses dependency … |
@SocketSecurity |
Company |
Original |
2026-01-06 |
767 |
3 |
3 |
0 |
0 |
1 |
| 🧨 GitHub Actions pricing took a wild turn over the holidays: a proposed self-hosted runner billing change triggered imm… |
@SocketSecurity |
Company |
Original |
2026-01-06 |
2,149 |
3 |
1 |
0 |
1 |
0 |
| 🎙️In this episode of Engineering with AI, Socket CTO @AhmadNassri explains why so many AI workflows feel awkward today,… |
@SocketSecurity |
Company |
Original |
2026-01-05 |
251 |
3 |
1 |
0 |
0 |
0 |
| Socket research in The Hacker News this morning... ☕ |
@SocketSecurity |
Company |
Quote |
2025-12-29 |
2,233 |
10 |
1 |
0 |
0 |
0 |
| Add this episode to your podcast listening queue during the holidays. 🎧
Socket CTO @AhmadNassri talks through practica… |
@SocketSecurity |
Company |
Original |
2025-12-24 |
640 |
5 |
3 |
0 |
0 |
0 |
| 🚨 New research: A spearphishing campaign published 27 malicious npm packages that host browser-run lures mimicking docu… |
@SocketSecurity |
Company |
Original |
2025-12-23 |
1,144 |
7 |
4 |
0 |
0 |
3 |
| 🚨 Socket’s Threat Research Team uncovered two malicious "Phantom Shuttle" Chrome extensions masquerading as a VPN since… |
@SocketSecurity |
Company |
Original |
2025-12-22 |
1,510 |
9 |
5 |
0 |
0 |
2 |
| 🚀 Big News! Docker Hardened Images are now free! We’re partnering with @Docker to bundle Socket Firewall into supported… |
@SocketSecurity |
Company |
Original |
2025-12-17 |
3,669 |
155 |
8 |
0 |
1 |
2 |
| 🎁 The Nightmare Before Deployment
https://t.co/OOHgz7IIJA |
@SocketSecurity |
Company |
Original |
2025-12-16 |
2,366 |
8 |
3 |
0 |
1 |
0 |
| 🚨 New threat research: An impostor #NuGet package typosquatted a popular .NET tracing library and its author, using hom… |
@SocketSecurity |
Company |
Original |
2025-12-15 |
3,208 |
3 |
3 |
0 |
2 |
1 |
| We’re excited to see @deno_land 2.6 ship deno audit plus an experimental --socket flag! 🎉
Catch malicious packages an… |
@SocketSecurity |
Company |
Original |
2025-12-13 |
4,819 |
15 |
8 |
0 |
0 |
4 |
| ⚠️ Following increased scrutiny after React2Shell, new React Server Components vulns have been disclosed: high-severity… |
@SocketSecurity |
Company |
Original |
2025-12-12 |
4,936 |
6 |
1 |
0 |
1 |
2 |
| 🔮 "Magical Code from the Sky" - Modern apps run on mountains of open source code that almost no one is actually reviewi… |
@SocketSecurity |
Company |
Original |
2025-12-12 |
769 |
3 |
2 |
0 |
0 |
0 |
| npm has revoked classic tokens for publishing, pushing maintainers toward OIDC trusted publishing or granular tokens. B… |
@SocketSecurity |
Company |
Original |
2025-12-10 |
3,066 |
3 |
5 |
0 |
1 |
1 |
| 📌 If you got a GitHub permissions update notice from Socket today, we adjusted bot permissions to enable Socket Certifi… |
@SocketSecurity |
Company |
Original |
2025-12-05 |
589 |
5 |
0 |
0 |
1 |
0 |
| 🚨 Socket Threat Research: We found two malicious crates targeting Rust devs via typosquatting.
finch-rust mimics the le… |
@SocketSecurity |
Company |
Original |
2025-12-05 |
1,909 |
9 |
4 |
1 |
1 |
2 |
| 🚨 New from the Socket Research Team: Malicious Go packages impersonating Google's UUID library quietly exfiltrate encry… |
@SocketSecurity |
Company |
Original |
2025-12-05 |
958 |
10 |
4 |
0 |
0 |
2 |
| 📉 November CVE publications fell 25% YoY, but 2025 is still tracking 16.9% higher overall.
A reminder from @JGamblin: … |
@SocketSecurity |
Company |
Original |
2025-12-05 |
1,156 |
5 |
4 |
0 |
0 |
2 |
| #TypeScript 6.0 will be the last JS-based major release. TypeScript 7’s native toolchain (Corsa) is already testable, w… |
@SocketSecurity |
Company |
Original |
2025-12-04 |
641 |
7 |
3 |
0 |
0 |
0 |
| 🚨 React disclosed a critical (CVSS 10.0) RCE in React Server Components. If you use RSC (often via frameworks like Next… |
@SocketSecurity |
Company |
Original |
2025-12-03 |
1,289 |
16 |
2 |
0 |
0 |
3 |
| Seasonal nuisance on npm this morning: 420+ auto-generated elf-stats-* packages, many claiming “generated every two min… |
@SocketSecurity |
Company |
Original |
2025-12-03 |
2,089 |
5 |
3 |
1 |
1 |
0 |
| 🚨 New Socket Threat Research: We found a malicious Rust crate disguised as an EVM version helper that downloads & s… |
@SocketSecurity |
Company |
Original |
2025-12-02 |
3,394 |
16 |
5 |
1 |
1 |
1 |
| A reality for anyone scaling a team:
"What got you from zero to one is not what's going get you from one to 10. So yo… |
@SocketSecurity |
Company |
Original |
2025-12-02 |
382 |
1 |
1 |
0 |
0 |
1 |
| Congrats to the @bunjavascript team and @AnthropicAI on this big move! Good news for sustainability: same team, still M… |
@SocketSecurity |
Company |
Quote |
2025-12-02 |
1,033 |
3 |
2 |
0 |
0 |
0 |
| 🎙️ Why great products don't always win: Socket CEO @feross breaks down a hard truth for technical founders in this conv… |
@SocketSecurity |
Company |
Original |
2025-12-02 |
1,962 |
12 |
4 |
0 |
1 |
3 |
| 💪 |
@SocketSecurity |
Company |
Quote |
2025-11-30 |
820 |
3 |
0 |
0 |
0 |
3 |
| New research from Socket: We uncover how North Korean hackers are using npm, GitHub, and Vercel together to spread Otte… |
@SocketSecurity |
Company |
Original |
2025-11-26 |
13,698 |
46 |
14 |
5 |
4 |
17 |
| 🚨 Socket researchers uncovered a malicious Chrome extension that injects hidden #SOL transfers into Raydium swaps, quie… |
@SocketSecurity |
Company |
Original |
2025-11-25 |
1,174 |
13 |
4 |
1 |
0 |
4 |
| ⚠️ Update on the Shai Hulud v2 campaign:
We’ve confirmed 834 malicious packages and now see spillover into Maven Centr… |
@SocketSecurity |
Company |
Original |
2025-11-25 |
14,854 |
64 |
24 |
4 |
4 |
18 |
| 🤯 The number of affected packages is now 770. We'll keep updating the blog post as our investigation continues. |
@SocketSecurity |
Company |
Quote |
2025-11-24 |
13,279 |
52 |
11 |
0 |
0 |
10 |
| We have updated this list to include more than 500 packages and 700+ affected versions, as well as a technical analysis… |
@SocketSecurity |
Company |
Quote |
2025-11-24 |
6,209 |
16 |
4 |
0 |
1 |
2 |
| RT @feross: Webhooks for Alert Changes just dropped
No more refreshing dashboards. Socket now pushes every new, updat… |
@SocketSecurity |
Company |
Original |
2025-11-24 |
750 |
2 |
1 |
0 |
0 |
0 |
| 🚨 A new wave of the Shai-Hulud supply chain attack has hit npm, impacting packages across widely used projects from Asy… |
@SocketSecurity |
Company |
Original |
2025-11-24 |
41,205 |
50 |
20 |
1 |
10 |
17 |
| 🇪🇺 Big move for EU security: @enisa_eu has become a CVE Program Root, expanding its role in coordinated vulnerability … |
@SocketSecurity |
Company |
Original |
2025-11-21 |
430 |
2 |
1 |
0 |
0 |
0 |
| 🚀 Launch Week Day 5!
Today we’re introducing Webhook Events for Alert Changes → real-time notifications for every Socke… |
@SocketSecurity |
Company |
Original |
2025-11-21 |
294 |
2 |
1 |
1 |
0 |
0 |
| 🚀 Launch Week Day 4: Socket now scans OpenVSX extensions!
Your IDE extensions have root access to everything: your cod… |
@SocketSecurity |
Company |
Original |
2025-11-20 |
1,639 |
3 |
2 |
1 |
1 |
0 |
| Launch Week Day 3: We're announcing beta support for @bunjavascript and @vltpkg package managers in Socket! 🎉
Develope… |
@SocketSecurity |
Company |
Original |
2025-11-19 |
1,084 |
6 |
4 |
1 |
0 |
0 |
| 🚀 We’re kicking off another Socket Launch Week today!
Day 1 is a big one: Reachability for #Ruby is now in beta.
Ruby t… |
@SocketSecurity |
Company |
Original |
2025-11-17 |
347 |
2 |
1 |
1 |
0 |
0 |
| 🚨 New npm malware campaign uncovered: 7 malicious packages use Adspect cloaking and fake CAPTCHAs to hide redirects to … |
@SocketSecurity |
Company |
Original |
2025-11-17 |
639 |
1 |
2 |
0 |
0 |
1 |
| 🍵 You may have seen reports calling the latest npm spam campaign a “worm.”
It’s not. It’s the same TEA Protocol spam w… |
@SocketSecurity |
Company |
Original |
2025-11-15 |
2,720 |
7 |
3 |
0 |
1 |
0 |
| 🚨 Socket’s Threat Research Team uncovered a malicious Chrome extension posing as an #Ethereum wallet. It steals seed ph… |
@SocketSecurity |
Company |
Original |
2025-11-12 |
360 |
5 |
1 |
0 |
1 |
0 |
| 🇬🇧 Socket is heading to London for Black Hat Europe and BSides London!
We’re looking forward to connecting with the s… |
@SocketSecurity |
Company |
Original |
2025-11-11 |
1,960 |
2 |
1 |
1 |
1 |
0 |
| 🐝 It’s official: OWASP’s 2025 Top 10 now includes Software Supply Chain Failures.
Half of survey respondents ranked it… |
@SocketSecurity |
Company |
Original |
2025-11-09 |
2,739 |
8 |
2 |
0 |
1 |
3 |
| 🚨 New from Socket Threat Research: 9 malicious #NuGet packages deliver time-delayed destructive payloads, designed to c… |
@SocketSecurity |
Company |
Original |
2025-11-06 |
1,297 |
5 |
5 |
0 |
0 |
0 |
| “With Socket we can get ahead of threats and prevent malicious packages from being pulled down at all. That’s a huge ga… |
@SocketSecurity |
Company |
Original |
2025-11-06 |
1,942 |
4 |
1 |
1 |
1 |
0 |
| Check out Socket CTO @AhmadNassri at @WorkOS' Enterprise Ready Conf: Ahmad joined a panel discussing how enterprise se… |
@SocketSecurity |
Company |
Original |
2025-11-05 |
977 |
3 |
2 |
0 |
0 |
1 |
| Still installing npm packages like it’s 2020? Not all npm installs are treats. 🎃
On the @changelog podcast, @feross sh… |
@SocketSecurity |
Company |
Original |
2025-10-31 |
3,523 |
9 |
2 |
0 |
1 |
3 |
| 🧯The security community is pushing back against new claims that 80% of #ransomware attacks are AI-driven, a figure from… |
@SocketSecurity |
Company |
Original |
2025-10-31 |
4,142 |
6 |
2 |
1 |
2 |
2 |
| The #Ruby ecosystem is entering a new phase of governance for its core package tools. Ruby creator Matz assumes control… |
@SocketSecurity |
Company |
Original |
2025-10-29 |
356 |
4 |
2 |
0 |
0 |
0 |
| Socket threat researchers found 10 typosquatted npm packages that auto-run via postinstall, display fake CAPTCHAs, fing… |
@SocketSecurity |
Company |
Original |
2025-10-28 |
5,252 |
8 |
2 |
1 |
2 |
2 |
| 🚀 Socket Launch Day 5!
Malicious packages are infiltrating development environments before they ever reach production.… |
@SocketSecurity |
Company |
Original |
2025-10-24 |
939 |
3 |
2 |
1 |
0 |
0 |
| 📈 Who’s keeping up with CVE publishing and who’s gone quiet?
CNAPulse is a new open source dashboard that brings publis… |
@SocketSecurity |
Company |
Original |
2025-10-24 |
1,259 |
2 |
2 |
0 |
0 |
0 |
| 🚀 Socket Launch Week Day 4 is here: We’re bringing supply chain security to your CI/CD!
Today we're introducing GitHub… |
@SocketSecurity |
Company |
Original |
2025-10-23 |
564 |
3 |
1 |
3 |
1 |
2 |
| 🚀 Socket Launch Week Day 3:
We’re making Socket even easier to integrate into your workflows with today's feature rele… |
@SocketSecurity |
Company |
Original |
2025-10-22 |
897 |
2 |
1 |
1 |
0 |
1 |
| 🚨 #NuGet Malware: Our research team uncovered malicious NuGet packages impersonating Nethereum via a Cyrillic “e” (homo… |
@SocketSecurity |
Company |
Original |
2025-10-22 |
464 |
4 |
1 |
0 |
0 |
0 |
| 🚀 Socket Launch Week Day 2: Unify your security stack.
Today we’re introducing Socket Basics: a single platform for st… |
@SocketSecurity |
Company |
Original |
2025-10-21 |
313 |
1 |
1 |
1 |
0 |
0 |
| Can you believe it – we’re kicking off another Socket Launch Week! 🎉 We'll be announcing a new feature every day.
And … |
@SocketSecurity |
Company |
Original |
2025-10-20 |
941 |
5 |
2 |
2 |
0 |
0 |
| When a registry’s maintainers and stewards lose alignment, the entire ecosystem feels it. Ruby Central’s report on the … |
@SocketSecurity |
Company |
Original |
2025-10-14 |
2,698 |
2 |
0 |
0 |
1 |
0 |
| Socket researchers uncovered a pattern of threat actors using #Discord webhooks for command & control (C2) across n… |
@SocketSecurity |
Company |
Original |
2025-10-11 |
495 |
4 |
4 |
0 |
0 |
1 |
| 🚀 Socket now integrates with Bun 1.3’s new Security Scanner API! @bunjavascript users can now protect their projects fr… |
@SocketSecurity |
Company |
Original |
2025-10-10 |
6,993 |
20 |
8 |
1 |
2 |
4 |
| North Korea’s “Contagious Interview” campaign continues to weaponize npm: 338 malicious packages, 50K+ downloads. Lever… |
@SocketSecurity |
Company |
Original |
2025-10-10 |
1,511 |
6 |
3 |
0 |
0 |
1 |
| Did you know some actively exploited CVEs were missing from Google’s OSV feed because the vendor disputed them? That’s … |
@SocketSecurity |
Company |
Quote |
2025-10-10 |
398 |
3 |
0 |
0 |
0 |
0 |
| ⚠️ Google’s OSV just added 500+ new advisories, not from new vulns, but from fixing a long-standing policy that made di… |
@SocketSecurity |
Company |
Original |
2025-10-10 |
2,659 |
4 |
2 |
0 |
2 |
0 |
| 🚨 175 malicious npm packages (26k+ downloads) abused npm and unpkg to host credential-phishing infrastructure targeting… |
@SocketSecurity |
Company |
Original |
2025-10-09 |
643 |
5 |
3 |
0 |
0 |
0 |
| 🎙️ This discussion is live right now with @feross and @matteocollina and @lucamaraschi ! Tune in: |
@SocketSecurity |
Company |
Quote |
2025-10-08 |
1,086 |
5 |
2 |
0 |
0 |
1 |
| #Python 3.14 just dropped: the “π release.” 🥧It adds template string literals, deferred annotations, and subinterpreter… |
@SocketSecurity |
Company |
Original |
2025-10-08 |
466 |
1 |
1 |
0 |
0 |
0 |
| 🔥 Breaking: Former #RubyGems maintainers have launched the Gem Cooperative, a community-run RubyGems server with open g… |
@SocketSecurity |
Company |
Original |
2025-10-06 |
3,108 |
5 |
3 |
2 |
3 |
1 |
| 🐍 New on the Socket blog: PEP 810 adds 'lazy import' syntax to defer module loading until first use, cutting startup ti… |
@SocketSecurity |
Company |
Original |
2025-10-04 |
3,546 |
3 |
2 |
0 |
1 |
0 |
| 🎙️ Socket CEO @feross breaks down the recent npm attacks on @PodRocketpod: phishing campaigns, AI-weaponized exploits, … |
@SocketSecurity |
Company |
Original |
2025-10-02 |
8,829 |
7 |
1 |
0 |
1 |
3 |
| GitHub is overhauling npm security after the Shai-Hulud worm. Maintainers welcome the shift to stronger defaults, but a… |
@SocketSecurity |
Company |
Original |
2025-10-01 |
1,160 |
5 |
6 |
1 |
0 |
3 |
| Maintainer compromises used to be rare. Now they’re happening at an alarming rate, as seen in recent attacks. Today we’… |
@SocketSecurity |
Company |
Original |
2025-09-30 |
9,756 |
40 |
14 |
3 |
3 |
17 |
| Today we’re publishing research on 80 confirmed fraudulent candidates who applied for Socket engineering roles in the p… |
@SocketSecurity |
Company |
Original |
2025-09-17 |
2,940 |
26 |
11 |
0 |
0 |
4 |
| 🚨 Update: The "Shai-Hulud" supply chain attack has expanded to nearly 500 trojanized npm packages, including several fr… |
@SocketSecurity |
Company |
Original |
2025-09-16 |
5,579 |
43 |
14 |
2 |
4 |
12 |
| 🚨 Ongoing npm supply chain attack: multiple CrowdStrike packages were trojanized in the same campaign that hit Tinycolo… |
@SocketSecurity |
Company |
Original |
2025-09-16 |
12,932 |
41 |
22 |
1 |
7 |
12 |
| 🚨 Malicious update to @ctrl/tinycolor on npm is part of an active supply chain attack hitting 40+ packages across multi… |
@SocketSecurity |
Company |
Original |
2025-09-15 |
5,656 |
16 |
11 |
0 |
2 |
2 |
| After recent npm supply chain attacks, @pnpmjs 10.16 adds a setting to delay updating dependencies.
Tools like Taze an… |
@SocketSecurity |
Company |
Original |
2025-09-15 |
8,254 |
9 |
8 |
1 |
1 |
2 |
| 🚨 Phishing alert for Rust devs! Phony emails are targeting https://t.co/A1nD2WDtRR users, claiming a breach. No evidenc… |
@SocketSecurity |
Company |
Original |
2025-09-12 |
2,009 |
8 |
3 |
1 |
0 |
1 |
| 🚀 Socket Launch Week Day 5: Custom PR Alert Headers are here!
Add your team's security guidance directly to Socket's P… |
@SocketSecurity |
Company |
Original |
2025-09-12 |
992 |
4 |
1 |
1 |
0 |
0 |
| 🚀 Socket Launch Day 4: #Rust Support Is Now in Beta!
All users can now scan Cargo projects and generate SBOMs, includ… |
@SocketSecurity |
Company |
Original |
2025-09-11 |
375 |
4 |
0 |
0 |
0 |
0 |
| 🚀 Day 3 of Socket Launch Week: Announcing Socket Fix 2.0!
We updated Socket Fix to be much more powerful, with targete… |
@SocketSecurity |
Company |
Original |
2025-09-10 |
1,694 |
5 |
2 |
1 |
0 |
1 |
| 😅 We’ll let you know if anything changes |
@SocketSecurity |
Company |
Quote |
2025-09-10 |
1,707 |
8 |
1 |
0 |
0 |
0 |
| 🚀 Day 2 of Socket Launch Week!
We’re excited to introduce Tier 1 Reachability: our most precise #CVE triage yet. It cu… |
@SocketSecurity |
Company |
Original |
2025-09-09 |
1,468 |
7 |
1 |
1 |
0 |
1 |
| 🚨 BREAKING: The DuckDB npm account was compromised. Malicious versions of duckdb, duckdb-wasm, and more were published … |
@SocketSecurity |
Company |
Original |
2025-09-09 |
26,152 |
89 |
42 |
6 |
9 |
12 |
| 📦 The MCP Steering Committee has launched the official MCP Registry in preview, a hub for discovering & publishing … |
@SocketSecurity |
Company |
Original |
2025-09-09 |
1,814 |
9 |
4 |
0 |
1 |
6 |
| 🚀 We’re kicking off another Launch Week at Socket, with a new feature launching every day!
First up: Pull Request Stor… |
@SocketSecurity |
Company |
Original |
2025-09-08 |
3,893 |
8 |
4 |
1 |
1 |
0 |
| Phishing strikes npm again. Qix’s npm account was compromised, pushing malicious updates to widely used packages, many … |
@SocketSecurity |
Company |
Quote |
2025-09-08 |
3,480 |
9 |
6 |
2 |
1 |
0 |
| 🚨 Breaking: npm author Qix compromised. Malicious package versions published in projects that typically see hundreds of… |
@SocketSecurity |
Company |
Original |
2025-09-08 |
108,784 |
95 |
23 |
3 |
13 |
23 |
| 🚨 Socket’s Threat Research Team found 4 malicious npm packages impersonating Flashbots SDKs, designed to exfiltrate #Et… |
@SocketSecurity |
Company |
Original |
2025-09-05 |
373 |
1 |
0 |
0 |
0 |
0 |
| The Nx team’s investigation into last week’s supply chain attack found the compromise came from a GitHub Actions workfl… |
@SocketSecurity |
Company |
Original |
2025-09-03 |
2,169 |
10 |
3 |
0 |
2 |
0 |
| 🚨 Supply chain attack on Nx npm packages (4.6M weekly downloads)
Malware abused AI CLI tools (Claude, Gemini, Q) to st… |
@SocketSecurity |
Company |
Original |
2025-08-27 |
2,869 |
8 |
3 |
0 |
2 |
2 |
| 💎 Follow-up and clarification on our recent research into the malicious #Ruby gems campaign:
https://t.co/4ZtjIj0MNX |
@SocketSecurity |
Company |
Original |
2025-08-22 |
852 |
3 |
2 |
0 |
0 |
0 |
| ESLint is about to ship parallel linting, closing a 10-year-old feature request. 🚀
Benchmarks show 30–60% faster runs,… |
@SocketSecurity |
Company |
Original |
2025-08-22 |
2,726 |
10 |
6 |
0 |
0 |
0 |
| 🚨 A malicious Go module, disguised as an SSH brute-forcing tool, is sending stolen SSH logins to a hardcoded Telegram b… |
@SocketSecurity |
Company |
Original |
2025-08-21 |
337 |
1 |
1 |
0 |
0 |
0 |
| 🧹 New linter alert: @rspack_dev introduces Rslint, a TypeScript-first linter in Go powered by typescript-go.
Fast, typ… |
@SocketSecurity |
Company |
Original |
2025-08-20 |
1,789 |
16 |
4 |
0 |
1 |
2 |
| 1Password, Bitwarden, LastPass, Enpass, iCloud Passwords, and LogMeOnce remain vulnerable to zero-day clickjacking vuln… |
@SocketSecurity |
Company |
Original |
2025-08-19 |
1,872 |
9 |
4 |
0 |
0 |
2 |
| 🧹 Rust linters were fast but lacked type checks. The big news this week is that Oxlint is introducing type-aware lintin… |
@SocketSecurity |
Company |
Original |
2025-08-18 |
2,110 |
8 |
4 |
0 |
0 |
4 |
| 🚦Open washing, delayed open source, limited core… The new “Is It Really FOSS?” website tracks these trends and reviews … |
@SocketSecurity |
Company |
Original |
2025-08-16 |
11,178 |
9 |
4 |
0 |
2 |
2 |
| “Socket is an automation of what we do already, but faster and more reliable. It eliminates human error and saves us hu… |
@SocketSecurity |
Company |
Original |
2025-08-14 |
1,103 |
2 |
2 |
1 |
0 |
1 |
| 📦 Astral, makers of Ruff & uv, have launched pyx: a Python-native package registry in beta, built to speed installs… |
@SocketSecurity |
Company |
Original |
2025-08-14 |
3,440 |
27 |
7 |
1 |
0 |
2 |
| 🎙️Awesome to see Socket’s Martin Torp on Latio’s "On the Record" podcast with Omer Yair from @Ravencloudinc: Host @Jame… |
@SocketSecurity |
Company |
Original |
2025-08-13 |
920 |
2 |
2 |
1 |
0 |
0 |
| 🔐 npm Adopts OIDC for Trusted Publishing:
npm joins PyPI, RubyGems, and https://t.co/YE0k48qPib in enhancing security … |
@SocketSecurity |
Company |
Original |
2025-08-08 |
399 |
4 |
2 |
0 |
0 |
0 |
| 🚨 60 malicious Ruby gems. 275K+ downloads.
Socket researchers have uncovered a long-running, targeted credential thef… |
@SocketSecurity |
Company |
Original |
2025-08-08 |
2,397 |
11 |
2 |
0 |
1 |
3 |
| 🔥 Socket research on The Hacker News today: |
@SocketSecurity |
Company |
Quote |
2025-08-07 |
604 |
2 |
1 |
0 |
0 |
0 |
| 🚨 Socket researchers found two malicious npm packages targeting WhatsApp API devs.
Masquerading as socket libs, they u… |
@SocketSecurity |
Company |
Original |
2025-08-06 |
3,460 |
8 |
2 |
0 |
2 |
5 |
| TC39 just advanced 11 #JavaScript proposals, including Math.sumPrecise, base64/hex for Uint8Array, iterator chaining, a… |
@SocketSecurity |
Company |
Original |
2025-08-06 |
1,575 |
7 |
4 |
1 |
1 |
0 |
| 🚀 Day 4 of Launch Week: Introducing Rust support in Socket!
Search any crate on https://t.co/hse3Ft0hu0 — no login req… |
@SocketSecurity |
Company |
Original |
2025-07-31 |
1,101 |
2 |
1 |
0 |
1 |
0 |
| 🚀 Day 3 of Socket Launch Week: We’re launching Precomputed Reachability Analysis!
Socket takes a radically different … |
@SocketSecurity |
Company |
Original |
2025-07-30 |
1,092 |
4 |
3 |
1 |
0 |
0 |
| Day 2 of Socket Launch Week: DOUBLE LAUNCH 🚀
Browser extensions are a growing attack surface for nearly every organizat… |
@SocketSecurity |
Company |
Original |
2025-07-30 |
1,727 |
5 |
1 |
0 |
2 |
2 |
| Stay safe out there! https://t.co/Ju7ZJJdWmW |
@SocketSecurity |
Company |
Original |
2025-07-29 |
766 |
6 |
1 |
0 |
0 |
0 |
| 🚀 Day 2 of Socket Launch Week: Introducing Socket MCP for Claude Desktop!
Add one-click dependency security scanning t… |
@SocketSecurity |
Company |
Original |
2025-07-29 |
751 |
4 |
1 |
0 |
1 |
2 |
| 🚀 We’re kicking off a big launch week at Socket ahead of Black Hat, dropping a new feature every day this week!
Day 1… |
@SocketSecurity |
Company |
Original |
2025-07-28 |
3,514 |
3 |
2 |
0 |
1 |
1 |
| Vibe coding with LLMs is making developers faster, but also creating new attack surfaces. Socket CEO @feross talks with… |
@SocketSecurity |
Company |
Original |
2025-07-25 |
2,658 |
8 |
3 |
0 |
1 |
2 |
| 🚨 Supply chain attack alert: A threat actor gained access to @toptal’s GitHub org, making 73 repos public and injecting… |
@SocketSecurity |
Company |
Original |
2025-07-23 |
2,304 |
7 |
5 |
0 |
1 |
0 |
| "We tried a variety of different solutions, but Socket turned out to be the most cost-effective and efficient, replacin… |
@SocketSecurity |
Company |
Original |
2025-07-23 |
188 |
1 |
0 |
1 |
0 |
0 |
| 🚨 New Threat Research: We uncovered 4 malicious packages (3 on npm, 1 on PyPI) with 56,000+ downloads, all delivering s… |
@SocketSecurity |
Company |
Original |
2025-07-23 |
1,411 |
9 |
3 |
0 |
1 |
3 |
| 🚨 Attackers have hijacked the npm 'is' package (~2.8M weekly downloads), adding a malicious JS loader. This compromise … |
@SocketSecurity |
Company |
Original |
2025-07-22 |
3,513 |
8 |
6 |
1 |
2 |
1 |
| Bun 1.2.19 introduces isolated installs for monorepos, smarter package management, and 5x faster Bun.sql. 🎉 Congrats to… |
@SocketSecurity |
Company |
Original |
2025-07-22 |
6,122 |
84 |
12 |
2 |
1 |
9 |
| 🚨 Active supply chain attack on #npm: Multiple Prettier tooling packages were compromised through the phishing campaign… |
@SocketSecurity |
Company |
Original |
2025-07-19 |
10,043 |
23 |
15 |
0 |
3 |
4 |
| ✂️ Knip, the popular open source tool for finding unused code and dependencies, just hit 500 releases with v5.62.0. Thi… |
@SocketSecurity |
Company |
Original |
2025-07-18 |
249 |
4 |
1 |
0 |
0 |
0 |
| EU’s Cyber Resilience Act isn’t fully in effect yet but OSS maintainers are already bracing for compliance requests. cU… |
@SocketSecurity |
Company |
Original |
2025-07-17 |
296 |
1 |
2 |
0 |
0 |
1 |
| 🦀 Rust is the latest open source ecosystem to adopt Trusted Publishing, joining PyPI and RubyGems in moving away from l… |
@SocketSecurity |
Company |
Original |
2025-07-16 |
1,248 |
9 |
3 |
1 |
1 |
2 |
| 🚨 UPDATE: Socket's Threat Research Team continues tracking the spread of protestware targeting Russian language users. … |
@SocketSecurity |
Company |
Original |
2025-07-16 |
2,184 |
3 |
2 |
0 |
1 |
0 |
| Our latest threat research is in The Hacker News today:
67 malicious npm packages and a new malware loader (XORIndex) … |
@SocketSecurity |
Company |
Quote |
2025-07-15 |
511 |
2 |
0 |
0 |
0 |
0 |
| 🚨 New research: North Korea’s Contagious Interview campaign is back, with 67 new malicious npm packages, a new malware … |
@SocketSecurity |
Company |
Original |
2025-07-14 |
2,432 |
3 |
2 |
0 |
1 |
1 |
| In Vegas for Black Hat or DEF CON? We're hosting 1:1s with @feross and the next edition of the much-loved Campfire Stor… |
@SocketSecurity |
Company |
Original |
2025-07-14 |
918 |
2 |
2 |
0 |
0 |
0 |
| 🚨 New open source AI #cybersecurity framework outperforms humans in both speed and cost. It handles pen testing tasks … |
@SocketSecurity |
Company |
Original |
2025-07-10 |
1,583 |
6 |
2 |
0 |
1 |
0 |
| 🦕 Deno 2.4 brings back bundling with esbuild, adds new tooling for dependency updates, and ships stable OpenTelemetry s… |
@SocketSecurity |
Company |
Original |
2025-07-09 |
342 |
3 |
1 |
0 |
0 |
0 |
| 🦀 Rust continues to reshape #JavaScript frontend tooling. @Browserslist-rs just got a major performance optimization: i… |
@SocketSecurity |
Company |
Original |
2025-07-04 |
1,773 |
12 |
6 |
0 |
0 |
1 |
| 🚨 New Research: We found 8 more malicious #Firefox extensions.
From fake games to OAuth credential theft and proxy-bas… |
@SocketSecurity |
Company |
Original |
2025-07-04 |
467 |
6 |
2 |
0 |
0 |
2 |
| 🎉 We’re already contributing to @CycloneDX and PURL through @EcmaTC54, now with an official seat at @EcmaIntl. Excited… |
@SocketSecurity |
Company |
Quote |
2025-07-03 |
2,836 |
9 |
4 |
0 |
0 |
0 |
| The official Go SDK for the Model Context Protocol (MCP) is now in development, with a stable release expected by Augus… |
@SocketSecurity |
Company |
Original |
2025-07-03 |
272 |
1 |
1 |
0 |
0 |
1 |
| 🏘️ "Potemkin Understanding" - a failure mode where LLMs appear to grasp a concept but only create the illusion of under… |
@SocketSecurity |
Company |
Original |
2025-07-02 |
3,394 |
5 |
1 |
0 |
2 |
1 |
| “Socket gives us high-signal alerts right in GitHub. It’s helped us automate security without slowing developers down.”… |
@SocketSecurity |
Company |
Original |
2025-07-01 |
948 |
4 |
2 |
1 |
0 |
0 |
| 🤖 AI slop is flooding open source bug bounty programs.
Now curl and @djangoproject are fighting back. Both have publish… |
@SocketSecurity |
Company |
Original |
2025-06-30 |
4,967 |
15 |
10 |
1 |
0 |
4 |
| 🪇🎉 ECMAScript 2025 is official!
Iterator Helpers, Set methods, JSON Modules, Promise.try, and more have landed in the s… |
@SocketSecurity |
Company |
Original |
2025-06-26 |
1,016 |
1 |
4 |
0 |
0 |
0 |
| Over the weekend, Node.js quietly added a homepage button linking to paid third-party support for EOL versions.
This co… |
@SocketSecurity |
Company |
Original |
2025-06-26 |
2,924 |
2 |
4 |
1 |
1 |
0 |
| 🚨 Contagious Interview returns:
North Korean threat actors just dropped 35 new malicious npm packages that use a HexEva… |
@SocketSecurity |
Company |
Original |
2025-06-25 |
969 |
7 |
4 |
0 |
0 |
2 |
| 🚨 The Socket Research Team has spotted a malicious #Python package typosquatting the popular 'passlib' library on PyPI:… |
@SocketSecurity |
Company |
Original |
2025-06-24 |
461 |
2 |
1 |
0 |
1 |
0 |
| From Yahoo to Netflix to Amplitude: Terry O’Daniel’s path from infra engineer to #CISO is full of lessons for security … |
@SocketSecurity |
Company |
Original |
2025-06-23 |
201 |
1 |
1 |
0 |
0 |
0 |
| 🚨 New Research: We uncovered hidden protestware in multiple #JavaScript UI toolkits on npm that disables all mouse-base… |
@SocketSecurity |
Company |
Original |
2025-06-18 |
866 |
3 |
2 |
0 |
0 |
1 |
| The solo maintainer for libxml2 is no longer accepting embargoed vulnerability reports, citing the unsustainable burden… |
@SocketSecurity |
Company |
Original |
2025-06-17 |
2,214 |
2 |
2 |
0 |
1 |
0 |
| 🚨 New Socket research on malicious browser extensions:
🔹 Fake Apple popups (tech support scams)
🔹 Wikipedia redirects … |
@SocketSecurity |
Company |
Original |
2025-06-13 |
486 |
1 |
2 |
0 |
1 |
0 |
| 📌 We've just released our 2025 #Blockchain & #Cryptocurrency Threat Report:
Learn more about how credential stealers… |
@SocketSecurity |
Company |
Original |
2025-06-12 |
166 |
3 |
1 |
0 |
0 |
0 |
| 📦Big news in the #JavaScript package management space this week: pnpm 10.12.1 is out with a new experimental global vir… |
@SocketSecurity |
Company |
Original |
2025-06-11 |
840 |
7 |
1 |
0 |
0 |
0 |
| Node.js just released Amaro 1.0, its official #TypeScript loader. This sets the stage for TypeScript support in Node to… |
@SocketSecurity |
Company |
Original |
2025-06-10 |
1,532 |
10 |
5 |
0 |
0 |
1 |
| Happening this Friday! Join us to learn how to cut vulnerability alert noise by 80% with reachability analysis. 📉 |
@SocketSecurity |
Company |
Quote |
2025-06-09 |
378 |
2 |
1 |
0 |
0 |
0 |
| 🚨 Think twice before chasing Instagram growth hacks. Socket researchers uncovered a PyPI package disguised as an #Insta… |
@SocketSecurity |
Company |
Original |
2025-06-06 |
6,161 |
12 |
8 |
0 |
2 |
0 |
| 🎉 Socket now supports pylock.toml, enabling secure, reproducible #Python builds with advanced scanning and full alignme… |
@SocketSecurity |
Company |
Original |
2025-06-05 |
2,068 |
3 |
2 |
0 |
1 |
0 |
| 🧨 Socket’s Threat Research team uncovered two npm packages disguised as utilities, which came with a hidden kill switch… |
@SocketSecurity |
Company |
Original |
2025-06-05 |
1,568 |
4 |
3 |
0 |
1 |
1 |
| 🚨 New from the Socket Research Team: Malicious #Ruby gems are impersonating Fastlane plugins to steal #Telegram tokens,… |
@SocketSecurity |
Company |
Original |
2025-06-03 |
1,936 |
4 |
1 |
0 |
1 |
1 |
| 🚨 New from the Socket Threat Research Team:
We uncovered 4 malicious npm packages targeting #Ethereum and #BSC wallets,… |
@SocketSecurity |
Company |
Original |
2025-06-02 |
310 |
8 |
1 |
1 |
0 |
0 |
| TC39 update: #JavaScript is getting some powerful new features!
✅ Array.fromAsync
✅ Error.isError
✅ `using` for explici… |
@SocketSecurity |
Company |
Original |
2025-06-02 |
225 |
4 |
1 |
0 |
0 |
0 |
| The @rustlang revolution in #JavaScript tooling continues! 🦀 @vite_js has released Rolldown-Vite, a technical preview o… |
@SocketSecurity |
Company |
Original |
2025-05-30 |
1,262 |
12 |
1 |
0 |
0 |
0 |
| 🚨 A single mistyped npm install can give an attacker remote access to wipe your entire codebase. This malicious package… |
@SocketSecurity |
Company |
Original |
2025-05-30 |
137 |
3 |
0 |
0 |
0 |
0 |
| 🚨 PyPI malware alert: A single malicious #Python package is silently hijacking #Solana wallets by monkey-patching key g… |
@SocketSecurity |
Company |
Original |
2025-05-29 |
4,531 |
10 |
2 |
0 |
3 |
2 |
| The OpenJS Foundation is now a CNA for 40 hosted #JavaScript projects, including ESLint, Express, webpack, Fastify, Ele… |
@SocketSecurity |
Company |
Original |
2025-05-29 |
293 |
2 |
2 |
0 |
0 |
0 |
| 🚀 Introducing Socket MCP: real-time dependency scoring for AI-generated code. Stop risky packages at the prompt:
🔹 Fit… |
@SocketSecurity |
Company |
Original |
2025-05-28 |
2,522 |
8 |
5 |
0 |
1 |
3 |
| NIST is now under federal audit for its management of the NVD, as delays and data gaps mount. Meanwhile, CISA faces maj… |
@SocketSecurity |
Company |
Original |
2025-05-27 |
1,379 |
2 |
1 |
0 |
1 |
0 |
| 🚨 Socket’s Threat Research Team has uncovered 60 npm packages using post-install scripts to silently exfiltrate hostnam… |
@SocketSecurity |
Company |
Original |
2025-05-23 |
2,451 |
10 |
5 |
0 |
1 |
3 |
| Microsoft just announced "TypeScript Native Previews."
🎉 The new Go-based compiler is now on npm for public testing, w… |
@SocketSecurity |
Company |
Original |
2025-05-23 |
345 |
3 |
2 |
0 |
0 |
0 |
| 🚨 We uncovered a malware campaign on npm targeting devs using #React, #Vue, #Vite, #Nodejs & the Quill rich text ed… |
@SocketSecurity |
Company |
Original |
2025-05-22 |
1,881 |
7 |
4 |
0 |
1 |
1 |
| ⛔ Open source maintainers are urging GitHub to let them block Copilot from submitting AI-generated issues and PRs to th… |
@SocketSecurity |
Company |
Original |
2025-05-20 |
1,187 |
13 |
6 |
0 |
0 |
0 |
| 🚨 Socket found a malicious npm plugin that backdoors Koishi chatbots, exfiltrating any message containing an 8-characte… |
@SocketSecurity |
Company |
Original |
2025-05-19 |
1,525 |
2 |
1 |
0 |
1 |
1 |
| The Node.js TSC has declined to endorse a feature bounty program, citing concerns over incentives, governance, and proj… |
@SocketSecurity |
Company |
Original |
2025-05-15 |
5,043 |
2 |
3 |
0 |
1 |
0 |
| 📦 Not all packages are what they seem.
In our 2025 mid-year threat report, we break down the top trends in how attacker… |
@SocketSecurity |
Company |
Original |
2025-05-14 |
2,716 |
8 |
4 |
0 |
2 |
2 |
| Latest update from CISA on its plan to kill off RSS feeds in favor of publishing updates on X: "We have paused immediat… |
@SocketSecurity |
Company |
Quote |
2025-05-14 |
1,168 |
2 |
1 |
1 |
0 |
0 |
| 🛠️ ESLint continues its journey to language-agnostic linting, now officially supporting HTML! This new integration brin… |
@SocketSecurity |
Company |
Original |
2025-05-13 |
4,879 |
7 |
5 |
1 |
1 |
2 |
| CISA has quietly killed off its RSS feeds for KEVs and cyber alerts, replacing an open, automation-friendly format with… |
@SocketSecurity |
Company |
Original |
2025-05-12 |
2,457 |
4 |
1 |
1 |
2 |
3 |
| 🤖 The MCP community just announced work on an official metaregistry to standardize AI tool discovery. It will enable ag… |
@SocketSecurity |
Company |
Original |
2025-05-09 |
2,722 |
8 |
2 |
0 |
3 |
2 |
| 🚨 Socket researchers discovered an npm package targeting #crypto traders. It hunts for wallet keys & #BullX credent… |
@SocketSecurity |
Company |
Original |
2025-05-08 |
2,063 |
6 |
5 |
0 |
1 |
2 |
| 🚨 The Socket Threat Research Team has discovered a set of malicious npm packages targeting macOS developers using the C… |
@SocketSecurity |
Company |
Original |
2025-05-07 |
1,268 |
5 |
7 |
0 |
0 |
2 |
| 🎟️ Ticket Giveaway!
We’re giving away 8 tickets to @BSidesTampa 2025 — a top-tier security conference!
Want to attend… |
@SocketSecurity |
Company |
Original |
2025-05-07 |
432 |
4 |
3 |
2 |
0 |
0 |
| The latest AI grift: fake security reports on bug bounty platforms.
They include vague reproduction steps, imaginary f… |
@SocketSecurity |
Company |
Original |
2025-05-07 |
1,704 |
6 |
3 |
0 |
1 |
2 |
| 🔥 Launch Day 5: We’re so excited to launch socket fix — a CLI tool that automatically upgrades vulnerable dependencies,… |
@SocketSecurity |
Company |
Original |
2025-04-25 |
5,467 |
4 |
4 |
1 |
3 |
2 |
| 🔥 Launch Week Day 4: Historical Analytics is now in beta! This is a massive upgrade to Socket’s visibility and reportin… |
@SocketSecurity |
Company |
Original |
2025-04-24 |
1,494 |
3 |
3 |
1 |
2 |
0 |
| 🚀 Launch Week Day 3: Introducing Module Reachability — now live in your Socket dashboard!
Today we’re rolling out our f… |
@SocketSecurity |
Company |
Original |
2025-04-23 |
2,500 |
5 |
1 |
2 |
2 |
0 |
| 🚀 Big news! Socket is acquiring Coana, bringing best-in-class reachability analysis to modern SCA! Coana's technology r… |
@SocketSecurity |
Company |
Original |
2025-04-23 |
15,791 |
18 |
7 |
6 |
5 |
3 |
| 🔥 Day 2 of Socket Launch Week!
Today we're shipping Repository Labels + Security Policies — a powerful way to organize… |
@SocketSecurity |
Company |
Original |
2025-04-22 |
115 |
2 |
0 |
1 |
0 |
0 |
| 🚨 Socket researchers uncovered malicious npm & PyPI packages posing as dev tools — stealing wallet seed phrases via… |
@SocketSecurity |
Company |
Original |
2025-04-22 |
326 |
4 |
1 |
1 |
0 |
1 |
| 🚀 We’re excited to announce our public beta support for .NET! Secure your NuGet dependencies from typosquatting, depend… |
@SocketSecurity |
Company |
Original |
2025-04-21 |
477 |
3 |
2 |
1 |
0 |
1 |
| 🚨 Malicious npm packages posing as #Telegram bot libraries are installing SSH backdoors and exfiltrating data from deve… |
@SocketSecurity |
Company |
Original |
2025-04-18 |
289 |
4 |
2 |
1 |
1 |
0 |
| 📌 Just two weeks after PEP 751 was accepted, Python’s new pylock.toml lock file format is already becoming a fast-emerg… |
@SocketSecurity |
Company |
Original |
2025-04-18 |
1,663 |
5 |
2 |
1 |
2 |
1 |
| 🚀 Socket's Go support is now generally available!
All users can now get automatic scanning and deep code analysis for G… |
@SocketSecurity |
Company |
Original |
2025-04-17 |
276 |
2 |
2 |
1 |
0 |
0 |
| 🚀 The @vltpkg team just launched real-time dependency analysis powered by Socket!
Developers can now explore supply cha… |
@SocketSecurity |
Company |
Original |
2025-04-17 |
4,855 |
10 |
7 |
1 |
2 |
0 |
| 🚩 CISA has extended MITRE’s contract by 11 months, avoiding a shutdown but leaving long-term governance issues unresolv… |
@SocketSecurity |
Company |
Original |
2025-04-16 |
2,453 |
10 |
5 |
0 |
2 |
1 |
| New research: A malicious npm package disguised as an #Advcash integration triggers a reverse shell during payment succ… |
@SocketSecurity |
Company |
Original |
2025-04-14 |
308 |
3 |
2 |
0 |
0 |
0 |
| At #VulnCon, NIST revealed that the NVD is scrapping its consortium plan, walking back last year’s promise of reform, w… |
@SocketSecurity |
Company |
Original |
2025-04-11 |
832 |
3 |
1 |
0 |
0 |
0 |
| 🚀 Big upgrade just dropped: we completely redesigned the Repositories page in the Socket dashboard!
Now it’s easier tha… |
@SocketSecurity |
Company |
Original |
2025-04-09 |
2,781 |
0 |
1 |
1 |
1 |
0 |
| ⚡️ Multiple critical deserialization vulnerabilities in PyTorch Lightning could lead to remote code execution when load… |
@SocketSecurity |
Company |
Original |
2025-04-08 |
209 |
2 |
1 |
0 |
0 |
0 |
| 🚀 Join Socket + @CSide, @Arcjet, & @incident_io for TWO epic rooftop parties during #RSAC and #BSidesSF 2025!
📅 Su… |
@SocketSecurity |
Company |
Original |
2025-04-04 |
280 |
1 |
1 |
0 |
0 |
0 |
| 🚨 NVD just reclassified 20,000 older CVEs as “Deferred.” The database is quietly removing them from its processing pipe… |
@SocketSecurity |
Company |
Original |
2025-04-04 |
477 |
1 |
1 |
0 |
1 |
0 |
| 🚨 North Korean threat actors are back - and scaling up. The #Lazarus Group is expanding its npm malware campaign with n… |
@SocketSecurity |
Company |
Original |
2025-04-04 |
462 |
5 |
4 |
0 |
0 |
0 |
| ✨ Big news for #Python packaging: Python has officially adopted a standardized lock file format to improve reproducibil… |
@SocketSecurity |
Company |
Original |
2025-04-01 |
637 |
6 |
4 |
1 |
0 |
0 |
| In open source #SAST news: @opengrep has restored fingerprint and metavariable support in JSON and SARIF outputs, addre… |
@SocketSecurity |
Company |
Original |
2025-03-31 |
281 |
3 |
2 |
0 |
0 |
0 |
| Security experts are warning that recent classification changes obscure the true scope of the NVD backlog as #CVE volum… |
@SocketSecurity |
Company |
Original |
2025-03-28 |
1,489 |
7 |
6 |
0 |
0 |
1 |
| 🚩 Obfuscation 101: Attackers use obfuscation to hide malware in open source packages. Learn how to spot these technique… |
@SocketSecurity |
Company |
Original |
2025-03-28 |
330 |
6 |
2 |
0 |
0 |
1 |
| Biome has released v2.0 beta with support for custom plugins, domain-specific linting, and multi-file analysis. The upd… |
@SocketSecurity |
Company |
Original |
2025-03-26 |
615 |
3 |
4 |
0 |
0 |
2 |
| 🚨 Next.js has patched a critical vulnerability that lets attackers bypass auth middleware in self-hosted apps. A deep … |
@SocketSecurity |
Company |
Original |
2025-03-24 |
3,093 |
16 |
7 |
0 |
1 |
7 |
| 🚀 Big news: Socket is now available on Google Cloud Marketplace!
With simplified procurement and consolidated billing,… |
@SocketSecurity |
Company |
Original |
2025-03-21 |
311 |
4 |
2 |
0 |
0 |
0 |
| The Node.js TSC officially voted to stop distributing Corepack. Future Node.js releases (i.e. 25+) won’t include it, bu… |
@SocketSecurity |
Company |
Original |
2025-03-20 |
782 |
2 |
3 |
0 |
0 |
0 |
| 📌 Just hours ago, the Node.js TSC officially voted to stop distributing Corepack. Future Node.js releases (i.e. 25+) wo… |
@SocketSecurity |
Company |
Original |
2025-03-19 |
613 |
6 |
2 |
2 |
0 |
0 |
| 📦 Our latest investigation of Black Basta's leaked chats shows how they were plotting to exploit open source package re… |
@SocketSecurity |
Company |
Original |
2025-03-19 |
846 |
3 |
3 |
0 |
0 |
0 |
| 🌟 Oxlint is now in beta with 500+ built-in rules and 2X faster #JavaScript linting. Next up: custom plugin support and … |
@SocketSecurity |
Company |
Original |
2025-03-18 |
11,760 |
27 |
7 |
1 |
0 |
9 |
| 🚨 In case you missed it over the weekend: A GitHub Actions supply chain attack compromised the popular 'tj-actions/chan… |
@SocketSecurity |
Company |
Original |
2025-03-17 |
378 |
4 |
2 |
0 |
0 |
0 |
| 🚨 Supply Chain Attack Alert for #Java Developers:
A malicious Maven package, typosquatting the popular 'scribejava-core… |
@SocketSecurity |
Company |
Original |
2025-03-14 |
415 |
3 |
2 |
0 |
0 |
0 |
| 🚀 Big news for TypeScript! Microsoft is porting the TypeScript compiler to Go, delivering 10x faster builds, lower memo… |
@SocketSecurity |
Company |
Original |
2025-03-11 |
897 |
4 |
5 |
0 |
0 |
0 |
| 🚨 The Socket Research Team has uncovered 6 new malicious npm packages linked to North Korea’s #Lazarus Group. These pac… |
@SocketSecurity |
Company |
Original |
2025-03-11 |
6,906 |
10 |
5 |
2 |
2 |
6 |
| 🎧 Socket CEO @feross joined @heytimwinkler on The Pair Program podcast to talk about the open web, open source security… |
@SocketSecurity |
Company |
Original |
2025-03-10 |
355 |
2 |
1 |
0 |
0 |
0 |
| Can companies add restrictions to the AGPL while still claiming its benefits? The @fsf says absolutely not, and they've… |
@SocketSecurity |
Company |
Original |
2025-03-06 |
1,714 |
3 |
4 |
0 |
1 |
0 |
| 🚨 Typosquatted Go packages → Hidden malware loader → Silent execution on Linux & macOS.
Our latest research uncovers … |
@SocketSecurity |
Company |
Original |
2025-03-05 |
347 |
4 |
1 |
1 |
0 |
3 |
| 🚨 Socket researchers have uncovered a typosquatting attack in the Go ecosystem, where malicious packages install a hidd… |
@SocketSecurity |
Company |
Original |
2025-03-04 |
432 |
5 |
3 |
1 |
0 |
3 |
| 🚨 Crypto's worst start to a year: $1.6B lost in just 2 months—already surpassing all of 2024. The $1.46B #Bybit hack, l… |
@SocketSecurity |
Company |
Original |
2025-03-04 |
970 |
4 |
4 |
0 |
0 |
0 |
| 🎮 INCREDIBLE #TypeScript achievement: Michigan TypeScript founder Dimitri Mitropoulos (@MiTypeScript) has gotten Doom … |
@SocketSecurity |
Company |
Original |
2025-02-28 |
932 |
4 |
3 |
1 |
0 |
0 |
| The @vltpkg team launched "reproduce" today, an #OSS tool verifying if npm packages match their source code. With recen… |
@SocketSecurity |
Company |
Original |
2025-02-27 |
1,071 |
9 |
5 |
0 |
0 |
1 |
| 🏴☠️ Another wild example of how threat actors abuse open source package registries: Socket researchers have uncovered … |
@SocketSecurity |
Company |
Original |
2025-02-25 |
905 |
5 |
3 |
0 |
0 |
1 |
| 🚨 The Socket Research Team discovered a malicious npm package stealing cryptocurrency wallet keys from developers and u… |
@SocketSecurity |
Company |
Original |
2025-02-25 |
526 |
4 |
4 |
0 |
0 |
2 |
| devenv is facing backlash after the recent 1.4 release silently introduced telemetry that also exfiltrated users' git r… |
@SocketSecurity |
Company |
Original |
2025-02-21 |
2,106 |
5 |
2 |
0 |
1 |
0 |
| 🚀 @TC39 wrapped up their Seattle meeting, advancing 9 #JavaScript proposals—including some to Stage 4! Exciting updates… |
@SocketSecurity |
Company |
Original |
2025-02-20 |
2,308 |
7 |
2 |
0 |
1 |
1 |
| 🦕 Big news in the world of #JavaScript runtimes: Deno 2.2 was released today with improved Node.js compatibility, enhan… |
@SocketSecurity |
Company |
Original |
2025-02-20 |
3,960 |
13 |
2 |
0 |
1 |
2 |
| The React team has updated its CRA migration guidance after community pushback. Now the docs explicitly acknowledge @vi… |
@SocketSecurity |
Company |
Original |
2025-02-19 |
420 |
3 |
2 |
0 |
0 |
1 |
| 🚀 Big news for Node.js developers! require(esm) has been backported to Node.js 20, removing a major roadblock for ESM a… |
@SocketSecurity |
Company |
Original |
2025-02-13 |
397 |
3 |
2 |
0 |
0 |
0 |
| “Socket has drastically reduced the cognitive load on our team by providing actionable alerts with minimal noise. Devel… |
@SocketSecurity |
Company |
Original |
2025-02-11 |
737 |
9 |
2 |
1 |
0 |
0 |
| 🚨 Create React App is officially deprecated! 🚨
With React 19 breaking create-react-app and no maintenance for years, th… |
@SocketSecurity |
Company |
Original |
2025-02-11 |
536 |
4 |
5 |
0 |
0 |
0 |
| The latest development in @deno_land's petition to cancel Oracle’s claim to the #JavaScript trademark: Oracle used Node… |
@SocketSecurity |
Company |
Original |
2025-02-07 |
1,794 |
5 |
2 |
1 |
0 |
1 |
| 📌 The @linuxfoundation is warning open source developers: Compliance with global sanctions is not optional. Accepting P… |
@SocketSecurity |
Company |
Original |
2025-02-07 |
969 |
4 |
2 |
0 |
0 |
1 |
| 🚨 New Research: Malicious Go Package Exploits Caching to Persist Undetected 🚨
Socket researchers discovered a backdoore… |
@SocketSecurity |
Company |
Original |
2025-02-04 |
682 |
6 |
8 |
0 |
0 |
0 |
| 🚀 Exciting news: Socket is now part of TC54! We're joining forces to help shape the future of SBOMs, CycloneDX, and PUR… |
@SocketSecurity |
Company |
Original |
2025-01-31 |
2,128 |
9 |
3 |
1 |
0 |
0 |
| 🚨 Socket researchers have discovered a malicious npm package "postcss-optimizer" that delivers BeaverTail malware, targ… |
@SocketSecurity |
Company |
Original |
2025-01-30 |
1,399 |
10 |
7 |
0 |
0 |
1 |
| ⭐️ CISA's KEV data is now on GitHub, offering easier access, API integration, commit history tracking, and automated up… |
@SocketSecurity |
Company |
Original |
2025-01-29 |
439 |
6 |
3 |
0 |
0 |
0 |
| "Attackers are evolving their supply chain attacks and legacy tools aren’t catching them. Socket’s real-time threat det… |
@SocketSecurity |
Company |
Quote |
2025-01-27 |
1,524 |
6 |
3 |
0 |
0 |
2 |
| 📌 Node.js EOL versions just got their own CVE and critics are calling it “the worst CVE of the year.” Is this CVE a hel… |
@SocketSecurity |
Company |
Original |
2025-01-24 |
73,734 |
13 |
1 |
1 |
4 |
11 |
| ⚡️ Check out our latest case study to learn how @AnthropicAI leveraged Socket to:
- Automate 95% of dependency reviews… |
@SocketSecurity |
Company |
Original |
2025-01-24 |
1,643 |
4 |
0 |
0 |
1 |
0 |
| The cURL project and Go security teams are publicly rejecting CVSS as flawed for assessing vulnerabilities and are call… |
@SocketSecurity |
Company |
Original |
2025-01-24 |
5,332 |
14 |
8 |
1 |
3 |
2 |
| 🥟 Congrats to the @bunjavascript team on this major release: Bun 1.2 enhances its #JavaScript runtime with 90% Node.js … |
@SocketSecurity |
Company |
Original |
2025-01-22 |
779 |
9 |
1 |
0 |
1 |
1 |
| In an extraordinarily unpopular move, Fluent Assertions has dropped the Apache license in favor of a non-open source li… |
@SocketSecurity |
Company |
Original |
2025-01-18 |
896 |
2 |
2 |
5 |
1 |
0 |
| Another typosquatting attack on PyPI: This malicious #Python package exfiltrates #Discord authentication tokens and est… |
@SocketSecurity |
Company |
Original |
2025-01-16 |
257 |
3 |
1 |
0 |
0 |
0 |
| Dependency confusion is a real threat, but ethical research matters. Let’s protect the open source ecosystem without ad… |
@SocketSecurity |
Company |
Original |
2025-01-15 |
1,258 |
4 |
1 |
0 |
1 |
0 |
| 🚨 Socket researchers have uncovered multiple malicious npm packages impersonating the popular Chalk and Chokidar projec… |
@SocketSecurity |
Company |
Original |
2025-01-13 |
2,522 |
12 |
6 |
1 |
1 |
3 |
| Big changes in @pnpmjs 10.0.0: Lifecycle scripts are now blocked by default to combat supply chain attacks. This change… |
@SocketSecurity |
Company |
Original |
2025-01-10 |
3,437 |
9 |
2 |
0 |
2 |
3 |
| 🚀 Big news for #Python devs! Socket now supports uv.lock files, bringing deterministic dependency resolution and enhanc… |
@SocketSecurity |
Company |
Original |
2025-01-09 |
2,527 |
9 |
2 |
0 |
0 |
0 |
| 🚨 Socket researchers have discovered multiple malicious npm packages targeting #Solana private keys, abusing Gmail to e… |
@SocketSecurity |
Company |
Original |
2025-01-08 |
231 |
1 |
1 |
0 |
0 |
0 |
| On The Cyber Security Council podcast, @feross explains how Socket inspects open source packages for malicious activity… |
@SocketSecurity |
Company |
Original |
2025-01-08 |
634 |
2 |
1 |
0 |
0 |
0 |
| A new Python packaging proposal introduces SBOM support to tackle the "phantom dependency" problem, making it easier to… |
@SocketSecurity |
Company |
Original |
2025-01-07 |
278 |
3 |
1 |
0 |
0 |
0 |
| On The Cyber Security Council podcast, @feross explains how Socket helps developers evaluate open source risk at the e… |
@SocketSecurity |
Company |
Original |
2025-01-06 |
143 |
3 |
0 |
0 |
0 |
0 |
| Socket researchers uncover the many ways threat actors are abusing OAST techniques across the npm, PyPI, and RubyGems e… |
@SocketSecurity |
Company |
Original |
2025-01-03 |
2,872 |
4 |
2 |
1 |
1 |
1 |
| A malicious npm campaign is targeting #Ethereum developers by impersonating @HardhatHQ plugins and the @NomicFoundation… |
@SocketSecurity |
Company |
Original |
2025-01-02 |
279 |
3 |
1 |
0 |
1 |
2 |