Socket

フィード

記事のアイキャッチ画像
Socket and Seal Security Collaborate to Fix Critical npm Overrides Bug
Socket
Socket and Seal Security collaborate to fix a critical npm overrides bug, resolving a three-year security issue in the JavaScript ecosystem's most popular package manager.
2日前
記事のアイキャッチ画像
TypeScript is Porting Its Compiler to Go for 10x Faster Builds
Socket
TypeScript is porting its compiler to Go, delivering 10x faster builds, lower memory usage, and improved editor performance for a smoother developer experience.
3日前
記事のアイキャッチ画像
Lazarus Strikes npm Again with New Wave of Malicious Packages
Socket
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
3日前
記事のアイキャッチ画像
The Pair Program Podcast: Feross Aboukhadijeh on Preserving Trust in Open Source
Socket
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
3日前
記事のアイキャッチ画像
Opengrep Launches Playground in Alpha: A Faster, More Stable Environment for SAST Rule Development
Socket
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.
7日前
記事のアイキャッチ画像
Free Software Foundation Goes to Bat for AGPL in Amicus Brief Criticizing Neo4j’s License Infringement
Socket
FSF files an amicus brief against Neo4j, defending the AGPL and warning against adding restrictive terms that undermine free software rights.
7日前
記事のアイキャッチ画像
New PyPI Malware ‘set-utils’ Exfiltrates Ethereum Private Keys Through Blockchain Transactions
Socket
Malicious PyPI package ‘set-utils’ steals Ethereum private keys by exfiltrating them through blockchain transactions via the Polygon RPC.
9日前
記事のアイキャッチ画像
Typosquatted Go Packages Deliver Malware Loader Targeting Linux and macOS Systems
Socket
Malicious Go packages are impersonating popular libraries to install hidden loader malware on Linux and macOS, targeting developers with obfuscated payloads.
9日前
記事のアイキャッチ画像
Bybit Hack Puts Crypto Losses at $1.6B, Surpassing All of Last Year in Just Two Months
Socket
Bybit's $1.46B hack by North Korea's Lazarus Group pushes 2025 crypto losses to $1.6B in just two months, already surpassing all of 2024's $1.49B total.
10日前
記事のアイキャッチ画像
OpenSSF Launches Open Source Project Security Baseline to Strengthen Software Supply Chain
Socket
OpenSSF has published OSPS Baseline, an initiative designed to establish a minimum set of security-related best practices for open source software projects.
14日前