Socket
フィード

Nx Investigation Reveals GitHub Actions Workflow Exploit Led to npm Token Theft, Prompting Switch to Trusted Publishing
Socket
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.
2日前

AGENTS.md Gains Traction as an Open Format for AI Coding Agents
Socket
AGENTS.md is a fast-growing open format giving AI coding agents a shared, predictable way to understand project setup, style, and workflows.
2日前

Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Socket
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
7日前

Risky Biz Podcast: Making Reachability Analysis Work in Real-World Codebases
Socket
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
8日前

Nx npm Packages Compromised in Supply Chain Attack Weaponizing AI CLI Tools
Socket
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.
9日前

CISA’s 2025 SBOM Guidance Adds Hashes, Licenses, Tool Metadata, and Context
Socket
CISA’s 2025 draft SBOM guidance adds new fields like hashes, licenses, and tool metadata to make software inventories more actionable.
11日前

Follow-up and Clarification on Recent Malicious Ruby Gems Campaign
Socket
A clarification on our recent research investigating 60 malicious Ruby gems.
14日前

ESLint Adds Support for Parallel Linting, Closing 10-Year-Old Feature Request
Socket
ESLint now supports parallel linting with a new --concurrency flag, delivering major speed gains and closing a 10-year-old feature request.
14日前

Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials via Telegram
Socket
A malicious Go module posing as an SSH brute forcer exfiltrates stolen credentials to a Telegram bot controlled by a Russian-speaking threat actor.
15日前

Rspack Introduces Rslint, a TypeScript-First Linter Written in Go
Socket
Rspack launches Rslint, a fast TypeScript-first linter built on typescript-go, joining in on the trend of toolchains creating their own linters.
15日前