Socket

@socket.dev

Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. https://socket.dev

🎉 We're excited to announce that Socket is now available in the AWS Security Hub Extended plan. Apply your committed AWS spend and block malicious packages and extensions at install time, before they land in an employee laptop, agent sandbox, or CI pipeline. socket.dev/blog/aws-sec...

AWS Security Hub Adds Socket for Supply Chain Security - Soc...

Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

socket.dev

🚨 Another npm worm is live right now. It landed the same week npm turned on publish-time malware scanning, and after npm killed long-lived tokens in favor of OIDC trusted publishing. It propagates through trusted publishing. keyv@6.0.0 even shipped with passing provenance.

🚨 Update: Watching this npm worm propagate in real time, we’re now tracking 2,234 affected package artifacts across 444 unique packages, and it’s still spreading. Average detection time: 5 min and 18 seconds after publication. Our campaign page includes all affected packages/versions.

Socket@socket.dev · yesterday

🚨 Active npm supply chain attack: keyv​@​6.0.0 and 13 other packages have been compromised. keyv alone gets 154M weekly downloads. The worm steals cloud and CI credentials, then uses stolen npm tokens to publish trojanized versions of more packages.

🚨 Active npm supply chain attack: keyv​@​6.0.0 and 13 other packages have been compromised. keyv alone gets 154M weekly downloads. The worm steals cloud and CI credentials, then uses stolen npm tokens to publish trojanized versions of more packages.

Bild

Today in AI: Anthropic disclosed that a Claude model published malware to PyPI during a security test, thinking it was in a simulation. In a separate incident, another model kept attacking a real company even after realizing the systems were probably real. socket.dev/blog/anthrop...

Claude Breached 3 Companies and Uploaded Malware to PyPI Dur...

A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to Py...

socket.dev

Wild case of what appears to be industrial espionage. The attackers found public code references to Alibaba’s private npm packages, then reused the names for unscoped package lures targeting developers with access to Alibaba’s internal tooling.

Socket@socket.dev · last wk.

A covert npm campaign targeting @alibabagroup.bsky.social developers split its loader across benign-looking packages. Combined, they deployed a cross-platform RAT that poisons AI tool skills for persistence and spreads laterally through DingTalk. socket.dev/blog/npm-rat...

A covert npm campaign targeting @alibabagroup.bsky.social developers split its loader across benign-looking packages. Combined, they deployed a cross-platform RAT that poisons AI tool skills for persistence and spreads laterally through DingTalk. socket.dev/blog/npm-rat...

Distributed npm Package Cluster Delivers Cross-Platform RAT ...

Benign-looking npm packages split malicious functionality across a dependency chain that deploys a cross-platform RAT targeting Alibaba developers.

socket.dev

🚨 Two Joyfill npm beta releases were compromised with an import-time implant that resolves encrypted payloads through Tron, Aptos, and BNB Smart Chain transactions to load a Node.js RAT: • @joyfill/layouts@0.1.2-2773.beta.0 • @joyfill/components@4.0.0-rc24-2773-beta.4

Bild

🔺 @nuxt.com has patched multiple security vulnerabilities, including a high-severity server-side RCE through server island props. Free Certified Patches are now available to help teams remediate affected versions until they can safely upgrade. socket.dev/blog/patches...

Socket Releases Free Certified Patches for Nuxt Security Vul...

Socket releases free Certified Patches for high-severity Nuxt vulnerabilities, including server-side remote code execution through server island props...

socket.dev

"Socket was the right fit for how we wanted our vulnerability management program to evolve. We wanted to move from reporting toward fixing and preventing, and the tooling we had before was not going to get us there." — Robert Phan, CISO, ID.​me

Bild

A fake corepack site at corepack[.]org is impersonating the Node.js Corepack tool and pushing malware to developers. The download button drops an infostealer that steals browser data and SSH keys, plus proxyware that turns your machine into a proxy node. socket.dev/blog/fake-co...

Fake Corepack Site Distributes Infostealer and Proxyware to ...

A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

socket.dev

🔺 New research: Malicious Packagist development versions exposed a large-scale GitHub Actions abuse campaign. Compromised repositories launch runners to exploit a cPanel & WHM authentication bypass, then harvest credentials and other server-side secrets. socket.dev/blog/github-...

Large-Scale GitHub Actions Abuse Powers a Distributed cPanel...

A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

socket.dev

🧪 A new independent study tested 5 frontier LLMs on 200k coding prompts. All 5 generated the same nonexistent package names. After review by PyPI Security and Socket, 53 remained available to register on PyPI or npm as potential slopsquatting targets. socket.dev/blog/slopsqu...

New Study Identifies 53 Slopsquatting Targets Across 5 Front...

Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.

socket.dev

🔺 New research: Malicious Packagist development versions exposed a large-scale GitHub Actions abuse campaign. Compromised repositories launch runners to exploit a cPanel & WHM authentication bypass, then harvest credentials and other server-side secrets. socket.dev/blog/github-...

Large-Scale GitHub Actions Abuse Powers a Distributed cPanel...

A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

socket.dev

The White House launched a new initiative to coordinate AI-discovered vulnerabilities across government, critical infrastructure, and open source. No operating plan is public yet, even as federal vulnerability programs face massive backlogs and failures. socket.dev/blog/white-h...

White House Launches Gold Eagle Initiative to Manage Surge i...

The White House’s Gold Eagle Initiative aims to coordinate AI-discovered vulnerabilities, validate findings, and accelerate patching across critical s...

socket.dev

Shai-Hulud's downstream impact is still coming to light. The worm hit tens of thousands of GitHub repos, and the latest breach is Suno, whose leaked source code shows how it scraped YouTube, Deezer, and Genius to train its models. 🎩 First reported by @404media.co. socket.dev/blog/suno-br...

Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu...

A Shai-Hulud infection exposed Suno's source code, which shows the AI music startup stream-ripped tracks to train its models.

socket.dev

🎮 11 malicious NuGet tools posed as game cheats to deliver Windows malware that used Google Sheets to track hosts and enforce a remote ban list. Three of the payloads also let Telegram users remotely capture and receive screenshots from the host. socket.dev/blog/11-mali...

11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windo...

11 malicious NuGet tools pose as game cheats to deploy Windows payloads, track hosts, and use Google Sheets for telemetry and control.

socket.dev

🚨 Update: The jscrambler attacker published four more malicious releases: 8.16.0, 8.17.0, 8.18.0, and 8.20.0 with the same infostealer payload. In 8.18.0 and 8.20.0, the dropper moved out of preinstall and into package code, bypassing npm install --ignore-scripts. Upgrade to 8.22.0.

Socket@socket.dev · 4w ago

🚨 BREAKING: Socket has identified a supply chain attack targeting the popular jscrambler npm package. The compromised jscrambler@8.14.0 release uses a malicious preinstall hook to execute hidden Windows, macOS, or Linux binaries during npm install. socket.dev/blog/jscramb...