Socket
フィード
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
18時間前
Supply Chain Attack on Rspack npm Packages Injects Cryptojacking Malware
Socket
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
2日前
Skuld Infostealer Returns to npm with Fake Windows Utilities and Malicious Solara Development Packages
Socket
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.
3日前
Sonar to Acquire Tidelift, Scaling Open Source Maintainer Support
Socket
Sonar’s acquisition of Tidelift highlights a growing industry shift toward sustainable open source funding, addressing maintainer burnout and critical software dependencies.
3日前
Inside the Business of Ransomware: Insights from Reddit AMA with Ransomware Negotiators
Socket
Ransomware negotiators share how modern cybercriminals operate like corporations, using specialized teams, negotiation tactics, and reputation management.
4日前
PyPI on Ultralytics Supply Chain Attack: Poor CI/CD Practices to Blame, No Security Flaws in PyPI Exploited
Socket
PyPI confirms no security flaws were exploited in the Ultralytics supply chain attack and highlights improvements for safer package publishing.
8日前
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
Socket
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
10日前
Malicious npm Package Typosquats Popular TypeScript ESLint Plugin, Exfiltrates Data and Enables Remote Exploitation
Socket
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
10日前
Ultralytics PyPI Package Compromised Through GitHub Actions Cache Poisoning
Socket
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.
11日前
Malicious Maven Package Impersonating 'XZ for Java' Library Introduces Backdoor Allowing Remote Code Execution
Socket
Socket researchers found a malicious Maven package impersonating the legitimate ‘XZ for Java’ library, introducing a backdoor for remote code execution.
15日前