Sign in

Socket

@socket.dev
1.2K followers 382 following 699 posts

Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. socket.dev

PostsRepliesMedia
Socket @socket.dev · 5h
New UK AISI report: GPT-6 Astra reached malicious payload delivery in 29.2% of simulated CTF runs. In its supply chain attacks, it considered fake CVE reports, deceptive PR notes, and triggering a publisher workflow from an unmerged PR branch. socket.dev/blog/astra-s...
socket.dev
New AISI Report Details How GPT-6 Astra Turned CTF Challenges Into Supply Chain Attacks
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.
043
Socket @socket.dev · 29/09/2026
Gnarly GitLab exploit in the wild 😳
041
Socket @socket.dev · 29/09/2026
📦 upm is a new package manager written in TypeScript. It comes in at about 250 KB, uses Node.js built-ins to compete on install speed, has a #JavaScript API, and can install from npm, pnpm, and Bun lockfiles. A zippy experiment with Node.js: socket.dev/blog/upm-pac...
socket.dev
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
1146
Reposted by Socket
Socket @socket.dev · 25/09/2026
Maintainers spend countless hours keeping the open source projects we all rely on secure. Too often, that work is unpaid. Socket is proud to join @openjsf.org's new Security Stewardship Program to help fund the researchers and maintainers protecting Node.js. socket.dev/blog/openjs-...
socket.dev
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
0237
Reposted by Socket
bsidesberlin.bsky.social @bsidesberlin.bsky.social · 28/09/2026
Community events like ours couldn't happen without great partners, so we'd like to give a big shout-out to our sponsors: ✨ @aikidosecurity.bsky.social ✨ @semgrep.com ✨ @socket.dev Thank you for supporting #BSidesBerlin this year—we couldn't do it without you! 🙌 🫶
011
Reposted by Socket
David 🏳️‍🌈🦦🐈‍⬛🐧🎮🤠 @blue-labs.org · 26/09/2026
thank you!
042
Socket @socket.dev · 26/09/2026
Open source’s next chapter might be a thousand slightly different versions of the same software. socket.dev/blog/oj-vite...
162
Socket @socket.dev · 25/09/2026
Maintainers spend countless hours keeping the open source projects we all rely on secure. Too often, that work is unpaid. Socket is proud to join @openjsf.org's new Security Stewardship Program to help fund the researchers and maintainers protecting Node.js. socket.dev/blog/openjs-...
socket.dev
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
0237
Socket @socket.dev · 24/09/2026
🚨 Two GitHub Actions compromised in May’s Mini Shai-Hulud campaign are running malware again. The repositories were re-enabled with malicious release tags intact, putting thousands of downstream repositories at risk. socket.dev/blog/mini-sh...
socket.dev
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
173
Socket @socket.dev · 23/09/2026
Socket researchers found a malicious Firefox extension that poses as a PDF identity verifier to hijack Google accounts. It fetches its payload after installation, steals Google session cookies, and can silently reset the victim’s password. socket.dev/blog/firefox...
socket.dev
Malicious Firefox Extension Poses as PDF Identity Verifier to Hijack Google Accounts
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.
020
Socket @socket.dev · 23/09/2026
Compromised MemTensor packages hit npm and PyPI today. Check our analysis for affected versions, cleanup guidance, and updates. socket.dev/blog/memtens...
010
Socket @socket.dev · 23/09/2026
🚨 MemTensor’s npm and PyPI packages have been compromised. Four malicious releases, including the latest version on both registries, drop cross-platform Go binaries that steal npm, PyPI, GitHub, AWS, SSH and other developer secrets. socket.dev/blog/memtens...
socket.dev
MemTensor npm and PyPI Packages Compromised in Credential-Stealing Supply Chain Attack
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package M...
110
Socket @socket.dev · 22/09/2026
Lovable rewrote Vite’s dev server in Rust. OJ uses ~75% less memory, and Lovable now provisions sandboxes in 3 seconds instead of 14.5. Evan You thinks AI may make these tailored rewrites more common to where everyone "maintains their own slop fork.” socket.dev/blog/oj-vite...
socket.dev
Lovable’s OJ Rewrites Vite’s Dev Server in Rust as AI Lowers the Cost of Forking Open Source
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.
182
Reposted by Socket
boredchilada @cyfar.ca · 17/09/2026
@socket.dev PolinRider compromised nova-two-factor dev branches via GitHub accounts, targeting developer environments. - IOCs: PolinRider, visanduma/nova-two-factor@dev-main - #Malware #SupplyChain #ThreatIntel
socket.dev
PolinRider Hits Packagist
012
Reposted by Socket
NodeConf.eu @nodeconf.eu · 21/09/2026
🥁 𝐒𝐩𝐞𝐚𝐤𝐞𝐫 𝐀𝐧𝐧𝐨𝐮𝐧𝐜𝐞𝐦𝐞𝐧𝐭🎙️ Thrilled to have @mikolalysenko.bsky.social on the #NodeConfEU 2026 stage! He'll tell us the story of "𝐃𝐞𝐥𝐞𝐭𝐞 𝐚𝐥𝐥 𝐂𝐕𝐄𝐬." 🎟️Don't miss it out; secure your tickets www.nodeconf.eu
186
Socket @socket.dev · 18/09/2026
It's been one year since the Shai-Hulud npm worm was unleashed on the software supply chain, kicking off the worst year for npm security on record. It's now open source and has since torn through thousands of packages and organizations on its rampage. socket.dev/blog/happy-b...
socket.dev
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
084
Socket @socket.dev · 17/09/2026
We’re tracking more North Korea-linked PolinRider activity across GitHub and Packagist. New findings: 4 malicious dev versions, rewritten Git history, and obfuscated JavaScript planted in index.php and executed through PHP’s shell_exec() function. socket.dev/blog/polinri...
socket.dev
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
010
Reposted by Socket
Jerod Santo @jerod.bsky.social · 14/09/2026
Who's this writing on the @socket.dev blog?! It's me! socket.dev/blog/jerod-s...
socket.dev
Jerod Santo Joins Socket as Head of Media
Allow myself to introduce... myself.
293
Socket @socket.dev · 16/09/2026
GitHub added cache-mode to GitHub Actions, a new control that limits cache access at the workflow or job level to reduce cache poisoning, the technique behind several recent high-profile supply chain attacks on npm and PyPI. socket.dev/blog/github-...
socket.dev
GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.
193
Reposted by Socket
Sarah Gooding @sarahgooding.bsky.social · 11/09/2026
Open source registries are the fastest ways to distribute code at scale. Maintainers and registry operators should be ready for agents to exploit that reach, whether the ecosystem is their target or simply on the path to one.
021
Socket @socket.dev · 14/09/2026
🎉 We're excited to welcome @jerod.bsky.social to Socket as our first Head of Media. After more than a decade as one of the most trusted voices in developer media, he's setting his sights on supply chain security. Find out what he's cooking up at Socket. socket.dev/blog/jerod-s...
socket.dev
Jerod Santo Joins Socket as Head of Media
Allow myself to introduce... myself.
070
Reposted by Socket
Feross @feross.bsky.social · 12/09/2026
OpenAI confirmed its agents were behind the Ruby GemStuffer incident. Sandboxed during a training run without full internet access, they used the registry as a makeshift web browser to reach the open web. Story by @bobmcmillan.bsky.social with analysis from @socket.dev www.wsj.com/tech/ai/cybe...
wsj.com
https://www.wsj.com/tech/ai/cyberattack-by-rogue-ai-swarm-stokes-fears-of-out-of-control-agents-473a0352
293
Socket @socket.dev · 11/09/2026
Socket researchers found a malicious Twitch browser extension on Chrome and Firefox with 30,000+ reported users. It forwards full account-scoped OAuth tokens to a Russian bot service, exposing chat, whispers, and account settings. socket.dev/blog/malicio...
socket.dev
Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.
061
Reposted by Socket
Louis Grasset @louisgrasset.fr · 10/09/2026
Always make sure not to setup random extensions. Their permissions can allow A LOT
021
Socket @socket.dev · 11/09/2026
Anthropic reports biased reasoning and recklessness fueled Claude’s PyPI attack. Mythos 5 ignored signs it was on the real internet, published malware to PyPI, then used credentials leaked by a vendor’s scanner to access that vendor’s live database. socket.dev/blog/claude-...
socket.dev
Anthropic Identifies Biased Reasoning and Recklessness as Drivers of Claude’s PyPI Attack
Anthropic found biased reasoning and recklessness drove Claude Mythos 5 to publish malware on PyPI and compromise a security vendor.
061
Reposted by Socket
NodeConf.eu @nodeconf.eu · 09/09/2026
Shoutout to all #NodeConf EU 2026 #Sponsors and #Friends! Thank you! 💛 Your partnership is helping us create something truly special in the #Node.js #community! Our Sponsors @cloudflare.social @platformatic.dev @socket.dev @nxtedition.bsky.social @igalia.com @vlt.io Zephyr Cloud, Tether, typesense
2136
Socket @socket.dev · 09/09/2026
Socket researchers uncovered malicious Chrome and Firefox extensions stealing crypto traders’ session tokens and wallet data. The extensions target Axiom & Padre (now Terminal) users, collecting data automatically from logged-in accounts. socket.dev/blog/chrome-...
socket.dev
Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.
030
Socket @socket.dev · 04/09/2026
OpenAI’s GPT-6 Astra scored 100% on ExploitBench. But in simulated tests, it also attempted supply chain attacks against open source maintainers, using fake identities and legitimate contributions to build trust before submitting malicious code. Details→ socket.dev/blog/gpt-6-a...
socket.dev
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
2204
Socket @socket.dev · 01/09/2026
Today, we’re launching Microsoft Teams notifications in Socket! 🚀 Route organization alerts and supply chain attack campaign updates directly to Teams, with precise control over what reaches each channel.
261
Reposted by Socket
Socket @socket.dev · 01/09/2026
The Rustification of #JavaScript tooling continues: @pnpm.io 12 has been rewritten in Rust, with installs up to 90% faster in testing. Other highlights: project-aware global bins, registry revisions, and deterministic lockfiles for cyclic dependency graphs. socket.dev/blog/pnpm-12
socket.dev
pnpm 12’s Rust Rewrite Cuts Install Times by Up to 90%
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.
0175
Socket @socket.dev · 01/09/2026
The Rustification of #JavaScript tooling continues: @pnpm.io 12 has been rewritten in Rust, with installs up to 90% faster in testing. Other highlights: project-aware global bins, registry revisions, and deterministic lockfiles for cyclic dependency graphs. socket.dev/blog/pnpm-12
socket.dev
pnpm 12’s Rust Rewrite Cuts Install Times by Up to 90%
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.
0175
Socket @socket.dev · 31/08/2026
What happens when AppSec leaders set aside vendor rivalries at Black Hat? 🤔 Socket CTO @ahmadnassri.com joined a roundtable of leaders to tackle some of the most pressing issues in open source supply chain security. 🔥 Great panel + a few spicy takes → socket.dev/blog/oss-sup...
socket.dev
6 AppSec CTOs Debate Open Source Supply Chain Security at Black Hat
Socket CTO Ahmad Nassri joins AppSec leaders at Black Hat to discuss active malware, package manager risks, and software supply chain defense.
020
Socket @socket.dev · 31/08/2026
Socket researchers uncovered more FUNNULL-linked activity on Packagist: 13 malicious themes that expose site visitors to gambling redirects and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware and steals crypto wallet seeds. socket.dev/blog/packagi... #PHP
socket.dev
13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds
Thirteen malicious Packagist themes expose visitors on unpatched iPhones to a WebKit-to-kernel exploit chain that steals device data and wallet seeds.
010
Socket @socket.dev · 28/08/2026
🚨 10 malicious OpenAPI React Query Codegen versions were published to npm in a Mini Shai-Hulud attack through a comment-triggered workflow. All with valid provenance. Anyone who installed an affected version should treat the environment as compromised. socket.dev/blog/openapi...
socket.dev
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
130
Socket @socket.dev · 28/08/2026
Today we’re bringing Socket’s browser extension security to Edge! 🚀 Security teams can now continuously evaluate extensions from the Microsoft Edge Add-ons store and catch malicious behavior or risky changes as new versions are published. Available today: socket.dev/blog/edge-ex...
socket.dev
Socket Now Protects the Microsoft Edge Extension Ecosystem
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.
020
Socket @socket.dev · 27/08/2026
Socket researchers found 18 Chrome extensions and one Edge extension delivering a wallet drainer and credential-stealing payloads. In several cases, attackers acquired established extensions, then pushed malicious updates to users who already trusted them. socket.dev/blog/chrome-...
socket.dev
19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads
Socket researchers found 18 Chrome extensions and one Edge extension delivering a wallet drainer, credential theft, and other malicious payloads.
021
Socket @socket.dev · 26/08/2026
🚀 We’re excited to launch Socket for ClickUp, now in beta! Move security findings from discovery to assigned, trackable work in ClickUp, with the context teams need to resolve them.
110
Socket @socket.dev · 25/08/2026
🚀 Today we’re excited to launch Socket for Asana. The new integration turns Socket alerts into assigned, trackable Asana tasks and keeps both systems in sync as remediation moves forward.
120
Reposted by Socket
Socket @socket.dev · 22/08/2026
“Before Socket, the traditional SCA and SAST companies were looking at a very narrow appsec space. Socket looks at the supply chain holistically, across firewall, threat intel, and SCA. That lets you combine all of it with your security program and see the benefits fast.” - Mohit Bansal, Webflow
131
Reposted by Socket
Socket @socket.dev · 24/08/2026
Open VSX is unblocking extension IDs used by impostors in previous malware campaigns, allowing the legitimate projects behind those names to reclaim them. The same ID can now appear in malware records while pointing to a legitimate package today. socket.dev/blog/open-vs...
socket.dev
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
051
Socket @socket.dev · 24/08/2026
Open VSX is unblocking extension IDs used by impostors in previous malware campaigns, allowing the legitimate projects behind those names to reclaim them. The same ID can now appear in malware records while pointing to a legitimate package today. socket.dev/blog/open-vs...
socket.dev
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
051
Socket @socket.dev · 22/08/2026
“Before Socket, the traditional SCA and SAST companies were looking at a very narrow appsec space. Socket looks at the supply chain holistically, across firewall, threat intel, and SCA. That lets you combine all of it with your security program and see the benefits fast.” - Mohit Bansal, Webflow
131
Socket @socket.dev · 21/08/2026
PHP and Composer support is now in Beta for all Socket customers. 🚀 Scan #PHP projects for vulnerabilities and malicious Packagist packages, then cut through CVE noise with precomputed and full application reachability, now generally available. socket.dev/blog/php-and...
socket.dev
PHP and Composer Support Is Now in Beta
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.
030
Socket @socket.dev · 20/08/2026
Today we’re bringing Socket’s browser extension security to Firefox! Socket now scans all 97,000+ extensions in Mozilla’s official directory and monitors new releases for malware, credential theft, suspicious infrastructure, and behavior changes.
socket.dev
Socket Now Protects the Firefox Extension Ecosystem
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.
1103
Socket @socket.dev · 20/08/2026
Popular Rust crates compromised: Affected versions of arrayref, internment, and append-only-vec were modified to depend on proc-macro1, a malicious typosquat of proc-macro2. Its build script downloaded and executed malware during Cargo builds. Analysis: socket.dev/blog/popular...
socket.dev
Popular Rust Crates Compromised in Build-Time Supply Chain Attack
Three compromised Rust crates pulled in a malicious dependency that downloaded and executed cross-platform malware during Cargo builds.
0132
Socket @socket.dev · 19/08/2026
Socket Threat Researchers uncovered a 77-extension Firefox campaign. 40 steal wallet secrets and credentials. Another 37 posed as unrelated tools but displayed sports scores. Nine began as score apps before later updates turned them into wallet malware. socket.dev/blog/firefox...
socket.dev
77 Firefox Extensions Linked to Crypto Wallet and Credential Theft
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.
152
Reposted by Socket
Socket @socket.dev · 17/08/2026
NIST is asking the #cybersecurity industry how AI should reshape the NVD after cutting routine CVE enrichment. As of today, "Not Scheduled CVEs" outnumber active enrichment by nearly 14 to 1. Here's the latest → socket.dev/blog/nist-nv...
socket.dev
NIST Proposes AI-Enabled NVD Overhaul After Cutting Routine CVE Enrichment
NIST disclosed an unreleased AI tool called V-etalon and opened a broad inquiry into NVD modernization after years of automation plans produced no public enrichment system.
022
Reposted by Socket
David 🏳️‍🌈🦦🐈‍⬛🐧🎮🤠 @blue-labs.org · 08/08/2026
TY Socket ❤️
021
Socket @socket.dev · 17/08/2026
NIST is asking the #cybersecurity industry how AI should reshape the NVD after cutting routine CVE enrichment. As of today, "Not Scheduled CVEs" outnumber active enrichment by nearly 14 to 1. Here's the latest → socket.dev/blog/nist-nv...
socket.dev
NIST Proposes AI-Enabled NVD Overhaul After Cutting Routine CVE Enrichment
NIST disclosed an unreleased AI tool called V-etalon and opened a broad inquiry into NVD modernization after years of automation plans produced no public enrichment system.
022
Socket @socket.dev · 17/08/2026
AI agents choose dependencies and execute code with developer credentials. Security systems still assume humans make those calls. At AI Council 2026, @feross.bsky.social covers recent supply chain attacks and how defenders are gaining an edge. Watch the talk → socket.dev/blog/ai-agen...
socket.dev
How AI Agents Expand the Software Supply Chain Attack Surface
In his AI Council 2026 talk, Feross Aboukhadijeh covers recent package compromises, vulnerability discovery, and a more automated security model.
120