Socket
フィード

MCP Community Begins Work on Official MCP Metaregistry
Socket
The MCP community is launching an official registry to standardize AI tool discovery and let agents dynamically find and install MCP servers.
16時間前

Malicious npm Packages Use Telegram to Exfiltrate BullX Credentials
Socket
Socket uncovers an npm Trojan stealing crypto wallets and BullX credentials via obfuscated code and Telegram exfiltration.
1日前

Backdooring the IDE: Malicious npm Packages Hijack Cursor Editor on macOS
Socket
Malicious npm packages posing as developer tools target macOS Cursor IDE users, stealing credentials and modifying files to gain persistent backdoor access.
2日前

AI Slop Is Polluting Bug Bounty Platforms with Fake Vulnerability Reports
Socket
AI-generated slop reports are making bug bounty triage harder, wasting maintainer time, and straining trust in vulnerability disclosure programs.
3日前

Malicious PyPI Package Targets Discord Developers with Remote Access Trojan
Socket
The Socket Research team investigates a malicious Python package disguised as a Discord error logger that executes remote commands and exfiltrates data via a covert C2 channel.
4日前

NPM targeted by malware campaign mimicking familiar library names
Socket
Socket uncovered npm malware campaign mimicking popular Node.js libraries and packages from other ecosystems; packages steal data and execute remote code.
7日前

wget to Wipeout: Malicious Go Modules Fetch Destructive Payload
Socket
Socket's research uncovers three dangerous Go modules that contain obfuscated disk-wiping malware, threatening complete data loss.
8日前

Using Trusted Protocols Against You: Gmail as a C2 Mechanism
Socket
Socket uncovers malicious packages on PyPI using Gmail's SMTP protocol for command and control (C2) to exfiltrate data and execute commands.
9日前

A New Overview in our Dashboard
Socket
We redesigned Socket's first logged-in page to display rich and insightful visualizations about your repositories protected against supply chain threats.
10日前

Introducing Socket Fix for Safe, Automated Dependency Upgrades
Socket
Automatically fix and test dependency updates with socket fix—a new CLI tool that turns CVE alerts into safe, automated upgrades.
14日前