Socket

フィード

記事のアイキャッチ画像
2025 Report: Destructive Malware in Open Source Packages
Socket
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
2日前
記事のアイキャッチ画像
Engineering with AI Podcast: The Promise of AI-First Development
Socket
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.
2日前
記事のアイキャッチ画像
Spearphishing Campaign Abuses npm Registry to Target U.S. and Allied Manufacturing and Healthcare Organizations
Socket
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.
3日前
記事のアイキャッチ画像
Malicious Chrome Extensions “Phantom Shuttle” Masquerade as a VPN to Intercept Traffic and Exfiltrate Credentials
Socket
Fake “Phantom Shuttle” VPN Chrome extensions (active since 2017) hijack proxy auth to intercept traffic and continuously exfiltrate user credentials to attacker infrastructure.
3日前
記事のアイキャッチ画像
Socket Firewall Now Available in Docker Hardened Images
Socket
Socket Firewall Free is now bundled into Docker Hardened Images, adding build-time and dependency-install supply chain protection on top of hardened base images for Node.js, Python, and Rust.
9日前
記事のアイキャッチ画像
The Nightmare Before Deployment
Socket
Season’s greetings from Socket, and here’s to a calm end of year: clean dependencies, boring pipelines, no surprises.
9日前
記事のアイキャッチ画像
Malicious NuGet Package Typosquats Popular .NET Tracing Library to Steal Wallet Passwords
Socket
Impostor NuGet package Tracer.Fody.NLog typosquats Tracer.Fody and its author, using homoglyph tricks, and exfiltrates Stratis wallet JSON/passwords to a Russian IP address.
11日前
記事のアイキャッチ画像
Deno 2.6 + Socket: Supply Chain Defense In Your CLI
Socket
Deno 2.6 introduces deno audit with a new --socket flag that plugs directly into Socket to bring supply chain security checks into the Deno CLI.
13日前
記事のアイキャッチ画像
New React Server Components Vulnerabilities: DoS and Source Code Exposure
Socket
New DoS and source code exposure bugs in React Server Components and Next.js: what’s affected and how to update safely.
14日前
記事のアイキャッチ画像
Software Engineering Daily Podcast: Feross on AI, Open Source, and Supply Chain Risk
Socket
Socket CEO Feross Aboukhadijeh joins Software Engineering Daily to discuss modern software supply chain attacks and rising AI-driven security risks.
15日前