logo

Socket Blog

ID: c8d4bcaa-de7c-5bea-9992-5fcc84e2349e

STIX ID: identity--c8d4bcaa-de7c-5bea-9992-5fcc84e2349e

Feed Type: atom

Earliest post: 2026-05-31

Latest post: 2026-08-21

Socket fights vulnerabilities and provides visibility, defense-in-depth, and proactive supply chain protection for JavaScript, Python, and Go dependencies.

01/01/2020
08/24/2026
Title Date Published Describes IncidentAuthorVisible
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack2026-08-04TrueSocket Research TeamTrue
Claude Breached 3 Companies and Uploaded Malware to PyPI During Anthropic's Security Tests2026-07-31TrueSarah GoodingTrue
Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers2026-07-28TrueKarlo ZankiTrue
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan2026-07-28TrueSocket Research TeamTrue
Socket Releases Free Certified Patches for Nuxt Security Vulnerabilities2026-07-27TrueWenxin JiangTrue
Fake Corepack Site Distributes Infostealer and Proxyware to Developers2026-07-24TrueKirill BoychenkoTrue
Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign2026-07-22TrueKirill BoychenkoTrue
White House Launches Gold Eagle Initiative to Manage Surge in AI-Discovered Vulnerabilities2026-07-17TrueSarah GoodingTrue
Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Music Scraping2026-07-16TrueSarah GoodingTrue
Next.js moves to scheduled security releases2026-07-16TrueSarah GoodingTrue
11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload2026-07-14TrueKush PandyaTrue
Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader2026-07-14TrueSocket Research TeamTrue
Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates2026-06-29TrueKirill BoychenkoTrue
Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages2026-06-26TrueSocket Research TeamTrue
Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem2026-06-25TrueSocket Research TeamTrue
Frontier AI Is Now Critical Infrastructure2026-06-24TrueSarah GoodingTrue
GitHub Actions Checkout Now Blocks Risky pull_request_target Checkouts2026-06-20TrueSarah GoodingTrue
GlassWASM: WebAssembly Malware Found in Trojanized Open VSX Extensions2026-06-15TrueJoseph EdwardsTrue
152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search Traffic2026-06-12TrueKush PandyaTrue
npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders2026-06-09TrueSarah GoodingTrue
Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels2026-06-08TrueKirill BoychenkoTrue
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave2026-06-07TrueSocket Research TeamTrue
pnpm 11.5 Adds Support for Recognizing npm Staged Publishes2026-06-04TrueSarah GoodingTrue
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages2026-06-01TrueSocket Research TeamTrue
Famous Chollima Targets PHP Developers Through Compromised Packagist Package2026-05-31TrueKirill BoychenkoTrue

1–25 of 25