logo

Socket Blog

ID: c8d4bcaa-de7c-5bea-9992-5fcc84e2349e

STIX ID: identity--c8d4bcaa-de7c-5bea-9992-5fcc84e2349e

Feed Type: atom

Earliest post: 2026-05-31

Latest post: 2026-06-13

Socket fights vulnerabilities and provides visibility, defense-in-depth, and proactive supply chain protection for JavaScript, Python, and Go dependencies.

01/01/2020
06/13/2026
Title Date Published Describes IncidentAuthorVisible
152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search Traffic2026-06-12TrueKush PandyaTrue
npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders2026-06-09TrueSarah GoodingTrue
Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels2026-06-08TrueKirill BoychenkoTrue
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave2026-06-07TrueSocket Research TeamTrue
pnpm 11.5 Adds Support for Recognizing npm Staged Publishes2026-06-04TrueSarah GoodingTrue
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages2026-06-01TrueSocket Research TeamTrue
Famous Chollima Targets PHP Developers Through Compromised Packagist Package2026-05-31TrueKirill BoychenkoTrue

1–7 of 7