Socket
フィード

OpenClaw Skill Marketplace Emerges as Active Malware Vector
Socket
Security researchers report widespread abuse of OpenClaw skills to deliver info-stealing malware, exposing a new supply chain risk as agent ecosystems scale.
1日前

The Next Open Source Security Race: Triage at Machine Speed
Socket
Claude Opus 4.6 has uncovered more than 500 open source vulnerabilities, raising new considerations for disclosure, triage, and patching at scale.
4日前

Malicious dYdX Packages Published to npm and PyPI After Maintainer Compromise
Socket
Malicious dYdX client packages were published to npm and PyPI after a maintainer compromise, enabling wallet credential theft and remote code execution.
5日前

gem.coop Tests Dependency Cooldowns as Package Ecosystems Move to Slow Down Attacks
Socket
gem.coop is testing registry-level dependency cooldowns to limit exposure during the brief window when malicious gems are most likely to spread.
5日前

Open VSX Begins Implementing Pre-Publish Security Checks After Repeated Supply Chain Incidents
Socket
Following multiple malicious extension incidents, Open VSX outlines new safeguards designed to catch risky uploads earlier.
8日前

GlassWorm Loader Hits Open VSX via Developer Account Compromise
Socket
Threat actors compromised four oorzc Open VSX extensions with more than 22,000 downloads, pushing malicious versions that install a staged loader, evade Russian-locale systems, pull C2 from Solana memos, and steal macOS credentials and wallets.
10日前

Inside Lodash’s Security Reset and Maintenance Reboot
Socket
Lodash 4.17.23 marks a security reset, with maintainers rebuilding governance and infrastructure to support long-term, sustainable maintenance.
11日前

n8n Tops 2025 JavaScript Rising Stars as Workflow Platforms Gain Momentum
Socket
n8n led JavaScript Rising Stars 2025 by a wide margin, with workflow platforms seeing the largest growth across categories.
12日前

Federal Government Rescinds Software Supply Chain Mandates, Makes SBOMs Optional
Socket
The U.S. government is rolling back software supply chain mandates, shifting from mandatory SBOMs and attestations to a risk-based approach.
13日前

crates.io Ships Security Tab and Tightens Publishing Controls
Socket
crates.io adds a Security tab backed by RustSec advisories and narrows trusted publishing paths to reduce common CI publishing risks.
14日前