Socket
フィード

npm Malware Targets Telegram Bot Developers with Persistent SSH Backdoors
Socket
Malicious npm packages posing as Telegram bot libraries install SSH backdoors and exfiltrate data from Linux developer machines.
9時間前

Python Tools Are Quickly Adopting the New pylock.toml Standard
Socket
pip, PDM, pip-audit, and the packaging library are already adding support for Python’s new lock file format.
10時間前

Go Support Is Now Generally Available
Socket
Socket's Go support is now generally available, bringing automatic scanning and deep code analysis to all users with Go projects.
1日前

vlt Launches Real-Time Dependency Analysis Powered by Socket
Socket
vlt adds real-time security selectors powered by Socket, enabling developers to query and analyze package risks directly in their dependency graph.
1日前

CISA Extends MITRE Contract as Crisis Accelerates Alternative CVE Coordination Efforts
Socket
CISA extended MITRE’s CVE contract by 11 months, avoiding a shutdown but leaving long-term governance and coordination issues unresolved.
2日前

Rubygems Ecosystem Support Now Generally Available
1

Socket
Socket's Rubygems ecosystem support is moving from beta to GA, featuring enhanced security scanning to detect supply chain threats beyond traditional CVEs in your Ruby dependencies.
3日前

Malicious npm Package Disguised as Advcash Integration Triggers Reverse Shell
Socket
The Socket Research Team investigates a malicious npm package that appears to be an Advcash integration but triggers a reverse shell during payment success, targeting servers handling transactions.
4日前

Turtles, Clams, and Cyber Threat Actors: Shell Usage
Socket
The Socket Threat Research Team uncovers how threat actors weaponize shell techniques across npm, PyPI, and Go ecosystems to maintain persistence and exfiltrate data.
7日前

VulnCon 2025: NVD Scraps Industry Consortium Plan, Raising Questions About Reform
Socket
At VulnCon 2025, NIST scrapped its NVD consortium plans, admitted it can't keep up with CVEs, and outlined automation efforts amid a mounting backlog.
8日前

A New Design for GitHub PR Comments
1

Socket
We redesigned our GitHub PR comments to deliver clear, actionable security insights without adding noise to your workflow.
8日前