Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Socket

@SocketSecurity@fosstodon.org
mastodon 4.7.3
  • Open on fosstodon.org

Socket is a developer-first security platform that protects your code from both vulnerable and malicious dependencies. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS.

357 Followers
53 Following
47 Posts
Joined November 08, 2022
Socket:
https://socket.dev/
Open post
Socket @SocketSecurity@fosstodon.org
· 2w ago
It's been one year since the Shai-Hulud npm worm was unleashed on the software supply chain, kicking off the worst year for npm security on record. It's now open source and has since torn through thousands of packages and organizations on its rampage. https://socket.dev/blog/happy-birthday-shai-hulud
socket.dev
1
0
1
0
Open post
Socket @SocketSecurity@fosstodon.org
· 6mo ago

🚨 New Investigation: Attackers are hunting the maintainers behind Lodash, Fastify, buffer, Pino, mocha, Express, and #Nodejs core, because compromising one of them means write access to packages downloaded billions of times a week.

Multiple high-impact maintainers have all confirmed they were targeted in the same coordinated social engineering campaign that compromised Axios.

https://socket.dev/blog/attackers-hunting-high-impact-nodejs-maintainers

fosstodon.org
30
4
50
3
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago

LLM-assisted vulnerability discovery is raising patch volume across the industry and changing how projects ship security fixes.

Next.js is the latest to respond, moving to scheduled monthly releases starting July 20.

https://socket.dev/blog/nextjs-moves-to-scheduled-security-releases

socket.dev
4
0
1
0
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago

🔺 Nuxt has patched multiple security vulnerabilities, including a high-severity server-side RCE through server island props.

Free Certified Patches are now available to help teams remediate affected versions until they can safely upgrade.

https://socket.dev/blog/patches-for-nuxt-security-vulnerabilities

socket.dev
2
0
1
0
Open post
Socket @SocketSecurity@fosstodon.org
· 3mo ago
pnpm 11.10 adds a new _auth setting that ties each registry credential to its host, so a malicious or compromised repo file can't redirect your token to a different server. The release also hardens pnpm deploy, pack-app, and more. https://socket.dev/blog/pnpm-11-1-hardens-registry-authentication
socket.dev
3
0
2
0
Open post
Socket @SocketSecurity@fosstodon.org
· 5mo ago

🚨 BREAKING: Mini Shai-Hulud has spread to Packagist. We detected a malicious intercom/intercom-php@5.0.2 package artifact tied to this campaign.

The compromised #PHP package used Composer plugin execution to run during install/update, download Bun, and launch an obfuscated router_runtime.js credential-stealing payload.

It targeted GitHub, npm, SSH, cloud, Kubernetes, Vault, Docker, .env files, and more.

We reported it to Packagist, which removed the malicious version.

https://socket.dev/blog/mini-shai-hulud-packagist-malicious-intercom-php-package-compromise

fosstodon.org

Fosstodon

8
2
16
2
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago

🔺 New research: Malicious Packagist development versions exposed a large-scale GitHub Actions abuse campaign.

Compromised repositories launch runners to exploit a cPanel & WHM authentication bypass, then harvest credentials and other server-side secrets.

https://socket.dev/blog/github-actions-abuse-powers-cpanel-and-whm-exploitation

socket.dev
2
0
0
0
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago

🧪 A new independent study tested 5 frontier LLMs on 200k coding prompts. All 5 generated the same nonexistent package names.

After review by PyPI Security and Socket, 53 remained available to register on PyPI or npm as potential slopsquatting targets.

https://socket.dev/blog/slopsquatting-targets-across-frontier-llms

socket.dev
2
0
0
0
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago

🚨 Attackers compromised four npm packages in the @​asyncapi namespace to deliver the Miasma botnet loader.

The malware runs when an infected module is imported, then pulls an encrypted payload from IPFS across macOS, Linux, and Windows.

https://socket.dev/blog/asyncapi-supply-chain-attack

socket.dev
2
1
5
0
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago

🚨 BREAKING: Socket has identified a supply chain attack targeting the popular jscrambler npm package.

The compromised jscrambler@8.14.0 release uses a malicious preinstall hook to execute hidden Windows, macOS, or Linux binaries during npm install.

The malicious release was published today and detected by Socket 6 minutes later. Remove 8.14.0 and pin to 8.13.0 or another verified clean release.

https://socket.dev/blog/jscrambler-supply-chain-attack

socket.dev
2
0
1
1
Open post
Socket @SocketSecurity@fosstodon.org
· 3mo ago
Every package install brings third-party code into your app. On the @riskybiz@infosec.exchange podcast, Socket CEO @feross@infosec.exchange explains how AI coding agents are pulling in more dependencies, faster, often without a human in the loop. Watch the full episode: https://socket.dev/blog/risky-biz-podcast-ai-agents-raising-the-stakes
socket.dev
2
0
4
0
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago

A covert npm campaign targeting @alibabagroup@bird.makeup developers split its loader across benign-looking packages.

Combined, they deployed a cross-platform RAT that poisons AI tool skills for persistence and spreads laterally through DingTalk.

https://socket.dev/blog/npm-rat-targets-alibaba

socket.dev
1
0
0
0
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago

🚨 Two Joyfill npm beta releases were compromised with an import-time implant that resolves encrypted payloads through Tron, Aptos, and BNB Smart Chain transactions to load a Node.js RAT:

• @joyfill/layouts@0.1.2-2773.beta.0

• @joyfill/components@4.0.0-rc24-2773-beta.4

The RAT can execute JavaScript and shell commands, upload files, collect clipboard data, and persist through VS Code, Cursor, GitHub Desktop, and npm CLI files.

Full analysis: https://socket.dev/blog/joyfill-npm-beta-releases-compromised

socket.dev
1
0
1
0
Open post
Socket @SocketSecurity@fosstodon.org
· 6mo ago

🚨 Breaking: Newly pushed Trivy Docker images are compromised.

Tags 0.69.5 and 0.69.6 were published to Docker Hub on 3/22 without corresponding GitHub releases and contain the same infostealer IOCs. latest currently points to a malicious image.

Details: https://socket.dev/blog/trivy-docker-images-compromised

socket.dev
6
0
8
0
Open post
Socket @SocketSecurity@fosstodon.org
· 6mo ago

🚨 Active supply chain attack on axios@1.14.1. The latest version pulls in plain-crypto-js@4.2.1 -- a brand-new package that didn't exist before today.

We're still investigating. If you use axios, pin your version and audit your lockfile.

https://socket.dev/blog/axios-npm-package-compromised

socket.dev
5
0
16
0
Open post
Socket @SocketSecurity@fosstodon.org
· 6mo ago

🚨 TeamPCP is systematically targeting security tools across the #OSS ecosystem, turning scanners and CI pipelines into infostealers. Attacks spreading fast across GitHub Actions, Open VSX, and PyPI.

“These companies were built to protect your supply chains yet they can't even protect their own, the state of modern security research is a joke, as a result we're gonna be around for a long time stealing terrabytes of trade secrets with our new partners.”

Details → https://socket.dev/blog/teampcp-targeting-security-tools-across-oss-ecosystem

fosstodon.org
5
0
8
0
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago

RE: @SocketSecurity@fosstodon.org

🚨 Update: The jscrambler attacker published four more malicious releases: 8.16.0, 8.17.0, 8.18.0, and 8.20.0 with the same infostealer payload.

In 8.18.0 and 8.20.0, the dropper moved out of preinstall and into package code, bypassing npm install --ignore-scripts.

Jscrambler says an npm publishing credential was compromised. Upgrade to 8.22.0. We've updated our technical analysis.

fosstodon.org
1
0
1
0
Open post
Socket @SocketSecurity@fosstodon.org
· 5mo ago

RE: @bagder@mastodon.social

Awesome to see the fake stars research from CMU, NCSU, and Socket engineers featured on Awesome Agents! This is the origin of our "Suspicious Stars on GitHub" supply chain alert for packages that are associated with these repositories.

More info here:

https://socket.dev/blog/3-7-million-fake-github-stars-a-growing-threat-linked-to-scams-and-malware

https://socket.dev/changelog/new-alert-suspicious-stars-on-github

mastodon.social
3
0
3
0
Open post
Socket @SocketSecurity@fosstodon.org
· 3mo ago

🚨 Socket detected a software supply chain compromise in @​injectivelabs/sdk-ts, a popular npm package with ~50,000 weekly downloads and 87 npm dependents.

The malicious release hooks wallet key-derivation functions, records private keys and mnemonics, and exfiltrates them through fake telemetry.

The malicious 1.20.21 version was also pinned across 17 other @​injectivelabs scoped packages, exposing users who may not have installed the SDK directly.

https://socket.dev/blog/compromised-injective-sdk-npm-package

socket.dev
1
0
1
0
Open post
Socket @SocketSecurity@fosstodon.org
· 5mo ago

🚨 Bitwarden CLI 2026.4.0 was compromised as part of the ongoing Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.

We’ll continue updating our coverage as more details are confirmed.

https://socket.dev/blog/bitwarden-cli-compromised

socket.dev
3
0
14
0
Open post
Socket @SocketSecurity@fosstodon.org
· 6mo ago

🪲 @circl@social.circl.lu and the @gcve@social.circl.lu initiative launched its decentralized publishing ecosystem today alongside Vulnerability-Lookup 4.1.0.

Any CNA, CSIRT, or vendor with a disclosure policy can now publish vulnerability data without routing through a central authority.

https://socket.dev/blog/gcve-launches-decentralized-publishing-ecosystem

🎩 h/t @jgamblin@infosec.exchange @joshbressers@infosec.exchange

socket.dev
4
0
4
0
Open post
Socket @SocketSecurity@fosstodon.org
· 6mo ago

"The whole software supply chain is built on blind trust. You're downloading code from random people on the internet that you've never met, and you're like, let's just run it." - @feross@infosec.exchange on @tbpn@bird.makeup talking about the Axios compromise.

Full interview → https://socket.dev/blog/feross-on-tbpn-how-north-korea-hijacked-axios

socket.dev
3
4
1
0
Open post
Socket @SocketSecurity@fosstodon.org
· 5mo ago

🚀 Big news: Socket has acquired Secure Annex.

John Tuckner is joining the team, and we’re excited to expand our coverage across browsers, code editors, and AI tools.

Read more → https://socket.dev/blog/socket-acquires-secure-annex

socket.dev
2
0
2
0
Open post
Socket @SocketSecurity@fosstodon.org
· 5mo ago

Nobody reads the code before installing it.

That’s always been the reality of open source security, but now AI is massively increasing the amount of code being written and shipped.

@feross@infosec.exchange breaks it down in 10 minutes on @rohdeali@bird.makeup's podcast:

https://www.youtube.com/shorts/euRDj-xo00I

Full episode → https://socket.dev/blog/feross-10-minutes-or-less-podcast-nobody-reads-the-code

2
0
3
0
Open post
Socket @SocketSecurity@fosstodon.org
· 9mo ago

We’re excited to see @deno_land@fosstodon.org 2.6 ship deno audit plus an experimental --socket flag! 🎉

Catch malicious packages and supply chain attacks before they land:

Run deno audit --socket to get Socket Firewall checks for npm dependencies right in the CLI.

https://socket.dev/blog/deno-2-6-socket-supply-chain-defense-in-your-cli

socket.dev
4
0
6
0
Open post
Socket @SocketSecurity@fosstodon.org
· 7mo ago

AI is changing how software gets built, and how it gets compromised. What's keeping your security team up at night? We want to hear about it. Book time with @feross@infosec.exchange and the Socket team at RSA + @bsidessf@infosec.exchange. We'll be in SF all week.

https://socket.dev/blog/meet-socket-team-at-rsac-and-bsidessf-2026

socket.dev
2
0
1
0
Open post
Socket @SocketSecurity@fosstodon.org
· 6mo ago

RE: @SocketSecurity@fosstodon.org

📌 Update: There are emerging claims of mass credential exfiltration: reports from @intcyberdigest@bird.makeup and @vxunderground@infosec.exchange cite ~300GB of credentials exfiltrated and ~500,000 stolen via the LiteLLM compromise alone.

Our post has been updated with the latest details:

fosstodon.org

Socket: "🚨 TeamPCP is systematically targeting security to…" - Fosstodon

1
0
3
0
Open post
Socket @SocketSecurity@fosstodon.org
· 17mo ago

🚀 The @vltpkg@fosstodon.org team just launched real-time dependency analysis powered by Socket!

Developers can now explore supply chain risks directly in their graph, with rich security metadata from Socket built in.

More on the integration → https://socket.dev/blog/vlt-launches-real-time-dependency-analysis-powered-by-socket #JavaScript

socket.dev
5
0
2
0
Open post
Socket @SocketSecurity@fosstodon.org
· 19mo ago

The @vltpkg@fosstodon.org team launched "reproduce" today, an #OSS tool that independently verifies whether published npm packages can be faithfully rebuilt from their source code. With recent supply chain attacks exposing provenance limitations, this innovative approach is already showing better adoption rates than traditional methods. Check it out ➳

https://socket.dev/blog/vlt-launches-reproduce #JavaScript

fosstodon.org
1
0
4
0
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago
RE: https://fosstodon.org/@SocketSecurity/117037191878959877 🚨 Update: Watching this npm worm propagate in real time, we’re now tracking 2,234 affected package artifacts across 444 unique packages, and it’s still spreading. Average detection time: 5 min and 18 seconds after publication. Check out our campaign page for all affected packages/versions.
fosstodon.org
0
0
1
0
Open post
Socket @SocketSecurity@fosstodon.org
· 5mo ago

New Research: Malicious Ruby gems and Go modules impersonated developer tools to steal secrets and poison CI.

Socket researchers found credential theft, GitHub Actions tampering, fake Go wrappers, proxy manipulation, and SSH persistence.

https://socket.dev/blog/malicious-ruby-gems-and-go-modules-steal-secrets-poison-ci #golang

socket.dev
0
0
3
0
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago

A fake corepack site at corepack[.]org is impersonating the Node.js Corepack tool and pushing malware to developers.

The download button drops an infostealer that steals browser data and SSH keys, plus proxyware that turns your machine into a proxy node.

https://socket.dev/blog/fake-corepack-site-distributes-infostealer-and-proxyware

socket.dev
0
0
0
0
Open post
Socket @SocketSecurity@fosstodon.org
· 6mo ago

🚨 TeamPCP compromised the Telnyx #Python SDK on PyPI.

Malicious versions 4.87.1 and 4.87.2 steal credentials.

Full analysis → https://socket.dev/blog/telnyx-python-sdk-compromised

fosstodon.org

Fosstodon

0
0
2
0
Open post
Socket @SocketSecurity@fosstodon.org
· 6mo ago

We're hiring for our first VP of Engineering at Socket.

You'll work directly with @feross@infosec.exchange to lead and scale a high-performing, deeply technical engineering team tackling some of the hardest problems in software supply chain security.

⚡️Apply here: https://jobs.ashbyhq.com/socket/09d8b0c5-6335-4edb-909e-00face1c9325

jobs.ashbyhq.com
0
0
1
0
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago

🎮 11 malicious NuGet tools posed as game cheats to deliver Windows malware that used Google Sheets to track hosts and enforce a remote ban list.

Three of the payloads also let Telegram users remotely capture and receive screenshots from the host.

https://socket.dev/blog/11-malicious-nuget-tools-pose-as-game-cheats

socket.dev
0
0
0
0
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago

"Socket was the right fit for how we wanted our vulnerability management program to evolve. We wanted to move from reporting toward fixing and preventing, and the tooling we had before was not going to get us there." — Robert Phan, CISO, ID.me

Learn how ID.me partnered with Socket to:

⚡ Get earlier visibility into supply chain threats
⚡ Give developers ownership of dependency risk
⚡ Block malicious packages with Socket Firewall

https://socket.dev/case-study/id-me

socket.dev
0
0
0
0
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago

The White House launched a new initiative to coordinate AI-discovered vulnerabilities across government, critical infrastructure, and open source.

No operating plan is public yet, even as federal vulnerability programs face massive backlogs and failures.

https://socket.dev/blog/white-house-gold-eagle-initiative-ai-discovered-vulnerabilities

socket.dev
0
0
0
0
Open post
Socket @SocketSecurity@fosstodon.org
· 6mo ago
Replying to
cc: @campuscodi@mastodon.social These seem like obviously shady links but all they need is to catch is a few tired developers. Even low conversion rates can yield meaningful results for attackers.
0
0
0
0
Open post
Socket @SocketSecurity@fosstodon.org
· 5mo ago

🚨 Supply chain attack: SAP CAP and Cloud MTA npm packages compromised. These package versions introduced new preinstall behavior that downloads and runs an external binary:

→ mbt@1.2.48
→ @cap-js/db-service@2.10.1
→ @cap-js/postgres@2.2.2
→ @cap-js/sqlite@2.2.2

Details: https://socket.dev/blog/sap-cap-npm-packages-supply-chain-attack

socket.dev
0
0
2
1
Open post
Socket @SocketSecurity@fosstodon.org
· 6mo ago

TeamPCP has partnered with ransomware group Vect after exfiltrating ~300GB of credentials from CI/CD environments, targeting open source supply chains.

“We will chain these compromises into devastating follow-on ransomware campaigns.”

Details → https://socket.dev/blog/teampcp-partners-with-vect-targeting-oss-supply-chains

socket.dev
0
0
4
0
Open post
Socket @SocketSecurity@fosstodon.org
· 6mo ago

New Research: 5 malicious npm packages typosquatting #crypto libraries steal private keys via Telegram, targeting #Solana and #Ethereum devs.

(Unrelated to recent TeamPCP attacks):

https://socket.dev/blog/5-malicious-npm-packages-typosquat-solana-and-ethereum-libraries-steal-private-keys #NodeJS

fosstodon.org
0
0
0
0
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago

Shai-Hulud's downstream impact is still coming to light. The worm hit tens of thousands of GitHub repos, and the latest breach is Suno, whose leaked source code shows how it scraped YouTube, Deezer, and Genius to train its models.

🎩 First reported by @404mediaco@mastodon.social
https://socket.dev/blog/suno-breach-shai-hulud-worm

socket.dev
0
0
2
0
Open post
Socket @SocketSecurity@fosstodon.org
· 6mo ago

🍻 Join Socket + @Docker@cloud-native.social for Happy Hour at #RSA: drinks, bites, and conversation with security engineers & open source maintainers.

Socket Firewall is now integrated into Docker Hardened Images, helping filter risky dependencies early.

📅 Wed 3/25, 4–6 PM

RSVP: https://luma.com/socket-docker-rsa-happy-hour

fosstodon.org
0
0
0
0
Open post
Socket @SocketSecurity@fosstodon.org
· 3mo ago

New Research: A fake Braintree SDK on NuGet is skimming live payment card data and stealing merchant credentials in production.

Its 14M download count is massively inflated to rank it right next to the real package.

Full analysis → https://socket.dev/blog/braintree-nuget-typosquat-skims-credit-cards

socket.dev
0
0
0
0
Open post
Socket @SocketSecurity@fosstodon.org
· 2mo ago

NVIDIA, Microsoft, Meta, Google, and OpenAI have joined a coalition of 50+ companies urging Washington not to restrict open models.

Their case: openness drives competition, keeps costs down, and strengthens security.

https://socket.dev/blog/the-ai-industry-is-betting-on-open-weights

socket.dev
0
0
2
0
Open post
Socket @SocketSecurity@fosstodon.org
· 6mo ago
Replying to
@marsup@mastodon.social Glad you weren't snared by it! Stay safe!
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:33:35 UTC