Socket

フィード

記事のアイキャッチ画像
npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders
Socket
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.
13時間前
記事のアイキャッチ画像
Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels
Socket
Newer packages in this compromise use native extensions and .pth loaders to execute JavaScript stealers in developer environments.
2日前
記事のアイキャッチ画像
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Socket
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
3日前
記事のアイキャッチ画像
RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems
Socket
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.
5日前
記事のアイキャッチ画像
pnpm 11.5 Adds Support for Recognizing npm Staged Publishes
Socket
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.
6日前
記事のアイキャッチ画像
Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD Backlog
Socket
Federal audit finds NIST lacked a plan to clear the NVD backlog, wasted funds on duplicate work, and delayed use of CISA data.
7日前
記事のアイキャッチ画像
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages
Socket
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.
9日前
記事のアイキャッチ画像
Famous Chollima Targets PHP Developers Through Compromised Packagist Package
Socket
The North Korean malware loader hides in a Packagist-listed package and its GitHub branch to fetch and execute remote code in a likely Contagious Interview-style lure.
10日前
記事のアイキャッチ画像
Rust Moves to Restrict LLM Use in Contributions After Months of Internal Debate
Socket
The Rust project is moving toward formal rules on LLM use in contributions after months of internal debate over maintainer burden, code quality, and contributor experience.
10日前
記事のアイキャッチ画像
Malicious NuGet Package Impersonates Sicoob SDK to Exfiltrate Banking Certificates and Passwords
Socket
A malicious NuGet package impersonating Sicoob exfiltrated client IDs, PFX passwords, and banking certificates through Sentry telemetry.
13日前