Socket

フィード

記事のアイキャッチ画像
OpenClaw Skill Marketplace Emerges as Active Malware Vector
Socket
Security researchers report widespread abuse of OpenClaw skills to deliver info-stealing malware, exposing a new supply chain risk as agent ecosystems scale.
1日前
記事のアイキャッチ画像
The Next Open Source Security Race: Triage at Machine Speed
Socket
Claude Opus 4.6 has uncovered more than 500 open source vulnerabilities, raising new considerations for disclosure, triage, and patching at scale.
4日前
記事のアイキャッチ画像
Malicious dYdX Packages Published to npm and PyPI After Maintainer Compromise
Socket
Malicious dYdX client packages were published to npm and PyPI after a maintainer compromise, enabling wallet credential theft and remote code execution.
5日前
記事のアイキャッチ画像
gem.coop Tests Dependency Cooldowns as Package Ecosystems Move to Slow Down Attacks
Socket
gem.coop is testing registry-level dependency cooldowns to limit exposure during the brief window when malicious gems are most likely to spread.
5日前
記事のアイキャッチ画像
Open VSX Begins Implementing Pre-Publish Security Checks After Repeated Supply Chain Incidents
Socket
Following multiple malicious extension incidents, Open VSX outlines new safeguards designed to catch risky uploads earlier.
8日前
記事のアイキャッチ画像
GlassWorm Loader Hits Open VSX via Developer Account Compromise
Socket
Threat actors compromised four oorzc Open VSX extensions with more than 22,000 downloads, pushing malicious versions that install a staged loader, evade Russian-locale systems, pull C2 from Solana memos, and steal macOS credentials and wallets.
10日前
記事のアイキャッチ画像
Inside Lodash’s Security Reset and Maintenance Reboot
Socket
Lodash 4.17.23 marks a security reset, with maintainers rebuilding governance and infrastructure to support long-term, sustainable maintenance.
11日前
記事のアイキャッチ画像
n8n Tops 2025 JavaScript Rising Stars as Workflow Platforms Gain Momentum
Socket
n8n led JavaScript Rising Stars 2025 by a wide margin, with workflow platforms seeing the largest growth across categories.
12日前
記事のアイキャッチ画像
Federal Government Rescinds Software Supply Chain Mandates, Makes SBOMs Optional
Socket
The U.S. government is rolling back software supply chain mandates, shifting from mandatory SBOMs and attestations to a risk-based approach.
13日前
記事のアイキャッチ画像
crates.io Ships Security Tab and Tightens Publishing Controls
Socket
crates.io adds a Security tab backed by RustSec advisories and narrows trusted publishing paths to reduce common CI publishing risks.
14日前