Sarah Gooding

@sarahgooding.bsky.social

VP of Communications at Socket (socket.dev). Open source and open web advocate, runner, knitter. Find me at sarahgooding.dev

A preview of where autonomous hacking may be heading: During a UK cyber test, a Mythos 5 agent used sockpuppets, spearphishing emails, and prompt injection to try to get an open source maintainer to merge malware. socket.dev/blog/ai-agen... #OpenSource #Cybersecurity

UK Cyber Test: AI Agent Attempted to Social Engineer Open So...

During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

socket.dev

🚨 Update: Watching this npm worm propagate in real time, we’re now tracking 2,234 affected package artifacts across 444 unique packages, and it’s still spreading. Average detection time: 5 min and 18 seconds after publication. Our campaign page includes all affected packages/versions.

Socket@socket.dev · 2d ago

🚨 Active npm supply chain attack: keyv​@​6.0.0 and 13 other packages have been compromised. keyv alone gets 154M weekly downloads. The worm steals cloud and CI credentials, then uses stolen npm tokens to publish trojanized versions of more packages.

After working with the @packagist.com team through recent supply chain attacks, it's clear how much they genuinely care about the health and security of PHP developers. They move fast & show up whenever the ecosystem needs them. If your company depends on Composer or Packagist, please support them.

Socket@socket.dev · 5d ago

Socket is a launch sponsor of the new Composer and @packagist.com sponsorship program. Packagist is critical infrastructure for millions of #PHP developers, and we're proud to fund the work that keeps it secure and open. socket.dev/blog/socket-...

Wild case of what appears to be industrial espionage. The attackers found public code references to Alibaba’s private npm packages, then reused the names for unscoped package lures targeting developers with access to Alibaba’s internal tooling.

Socket@socket.dev · last wk.

A covert npm campaign targeting @alibabagroup.bsky.social developers split its loader across benign-looking packages. Combined, they deployed a cross-platform RAT that poisons AI tool skills for persistence and spreads laterally through DingTalk. socket.dev/blog/npm-rat...

🚨 Two Joyfill npm beta releases were compromised with an import-time implant that resolves encrypted payloads through Tron, Aptos, and BNB Smart Chain transactions to load a Node.js RAT: • @joyfill/layouts@0.1.2-2773.beta.0 • @joyfill/components@4.0.0-rc24-2773-beta.4

Bild

🧪 A new independent study tested 5 frontier LLMs on 200k coding prompts. All 5 generated the same nonexistent package names. After review by PyPI Security and Socket, 53 remained available to register on PyPI or npm as potential slopsquatting targets. socket.dev/blog/slopsqu...

New Study Identifies 53 Slopsquatting Targets Across 5 Front...

Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.

socket.dev

Shai-Hulud's downstream impact is still coming to light. The worm hit tens of thousands of GitHub repos, and the latest breach is Suno, whose leaked source code shows how it scraped YouTube, Deezer, and Genius to train its models. 🎩 First reported by @404media.co. socket.dev/blog/suno-br...

Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu...

A Shai-Hulud infection exposed Suno's source code, which shows the AI music startup stream-ripped tracks to train its models.

socket.dev

🚨 Update: The jscrambler attacker published four more malicious releases: 8.16.0, 8.17.0, 8.18.0, and 8.20.0 with the same infostealer payload. In 8.18.0 and 8.20.0, the dropper moved out of preinstall and into package code, bypassing npm install --ignore-scripts. Upgrade to 8.22.0.

Socket@socket.dev · 4w ago

🚨 BREAKING: Socket has identified a supply chain attack targeting the popular jscrambler npm package. The compromised jscrambler@8.14.0 release uses a malicious preinstall hook to execute hidden Windows, macOS, or Linux binaries during npm install. socket.dev/blog/jscramb...

🚨 BREAKING: Socket has identified a supply chain attack targeting the popular jscrambler npm package. The compromised jscrambler@8.14.0 release uses a malicious preinstall hook to execute hidden Windows, macOS, or Linux binaries during npm install. socket.dev/blog/jscramb...

jscrambler npm Package Compromised in Supply Chain Attack - ...

A compromised jscrambler npm release added a malicious preinstall hook that runs hidden native binaries on Linux, macOS, and Windows.

socket.dev

🚨 Socket detected a software supply chain compromise in @​injectivelabs/sdk-ts, a popular npm package with ~50,000 weekly downloads and 87 npm dependents. The malicious release hooks wallet key-derivation functions, records private keys and mnemonics, and exfiltrates them through fake telemetry.

Bild

Node.js is weighing a controversial proposal to move more security reports into public workflows as AI-generated submissions surge. Maintainers say ending bug bounty rewards didn't reduce the volume, and many reports remain duplicated or low-signal. socket.dev/blog/nodejs-... #nodejs #javascript

Node.js Considers Public Workflow for Security Reports Amid ...

Node.js is debating whether AI-driven security report volume warrants moving more vulnerability reports into public workflows.

socket.dev

Surreal to see Socket sponsoring NodeConf EU. This is where I gave an impromptu talk on PeerCDN, my first startup, back in 2013, and where I met almost all my Node friends. Awesome to finally pay it forward.

NodeConf.eu@nodeconf.eu · last mo.

🚀Thrilled to announce @socket.dev as #gold Sponsors of #NodeConfEU 2026! 🌟 Socket is a #cybersecurity platform that protects companies from software supply chain attacks. Find out more👉 socket.dev Thank you! Your partnership is helping us create something truly special in the #Node.js community!

🚀 Socket Launch Week Day 5: Introducing Repository Access Permissions and Custom Roles. Custom Roles set what a user can do. Repository Access Permissions set which repos those actions apply to. Socket admins can now apply least-privilege access without forcing members into broad built-in roles.

Bild

🚀 Socket Launch Week Day 4: Socket MCP is getting a massive update! You can now review org alerts, inspect package artifacts, investigate suspicious packages, and use the Socket threat feed directly from your AI assistant.

🚀 Launch Week Day 3: Socket Firewall now blocks malicious code editor extensions. VS Code and Open VSX extensions run inside developer environments with access to source code, terminals, credentials, and tokens. Now teams can block bad extensions before install or update.

🚨 140+ Mastra npm packages were compromised in a supply chain attack published under the @​mastra/* namespace, including @​mastra/core (~918K weekly downloads). The attack used easy-day-js, a typosquatted dependency, to deliver a cross-platform infostealer. socket.dev/blog/mastra-...

140+ Mastra npm Packages Compromised in Coordinated Supply C...

More than 140 Mastra npm packages were compromised in a supply chain attack that used a typosquatted dependency to deliver a cross-platform infosteale...

socket.dev

🚀 Day 2 of Socket Launch Week: We’re excited to introduce Manifest Alerts! Socket now detects supply chain risks found in project manifests, starting with missing lockfiles that can make dependency installs non-reproducible.

Bild

📦 @pnpm.io 11.5 adds support for recognizing npm staged publishes after staged approval metadata triggered a false downgrade signal. As npm adds more release paths, registry metadata needs to make it clear how each package version was published. socket.dev/blog/pnpm-11...

pnpm 11.5 Adds Support for Recognizing npm Staged Publishes ...

pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publi...

socket.dev

Rust is moving toward a formal LLM contribution policy after months of heated internal debate, driven by a wave of low-effort "slop PRs" straining maintainers. The proposal bans LLM authorship but allows private use. socket.dev/blog/rust-mo...

Rust Moves to Restrict LLM Use in Contributions After Months...

The Rust project is moving toward formal rules on LLM use in contributions after months of internal debate over maintainer burden, code quality, and c...

socket.dev