//
sign in
Profile
by @danabra.mov
Profile
by @dansshadow.bsky.social
Profile
by @jimpick.com
AviHandle
by @danabra.mov
AviHandle
by @dansshadow.bsky.social
AviHandle
by @katherine.computer
EventsList
by @katherine.computer
ProfileHeader
by @dansshadow.bsky.social
ProfileHeader
by @danabra.mov
ProfileMedia
by @danabra.mov
ProfilePlays
by @danabra.mov
ProfilePosts
by @danabra.mov
ProfilePosts
by @dansshadow.bsky.social
ProfileReplies
by @danabra.mov
Record
by @atsui.org
Skircle
by @danabra.mov
StreamPlacePlaylist
by @katherine.computer
+ new component
Profile
Loading...
Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. https://socket.dev
Socket









Loading...
🚨 Mini Shai-Hulud/Miasma has now spread to PyPI. Socket found 37 malicious artifacts across 19 PyPI packages. The packages abuse #Python .pth startup behavior to launch a Bun-powered credential stealer targeting developer, cloud, and CI/CD secrets. socket.dev/blog/shai-hu...
🔥 Socket Firewall is now built into Replit's AI-powered development experience. It’s already blocking 8K malicious packages/day across builders on the platform, giving Replit users stronger protection by default at the moment dependencies are introduced. socket.dev/blog/socket-...
Big news for Socket: Andrew Becherer is joining as our first CISO. He brings deep experience leading security at high-growth SaaS companies, and will strengthen the security program behind the infrastructure we operate and the open source ecosystem we protect. socket.dev/blog/andrew-...
RubyGems 4.0.13 adds a cooldown feature to Bundler for newly published gems. The opt-in setting lets projects delay dependency resolution for new gem versions, reducing exposure during the short window when malicious releases often spread fastest. socket.dev/blog/rubygem...
Mini Shai-Hulud/Miasma/Hades is now targeting bioinformatics and MCP developers in a newer PyPI wave. We found 23 newly compromised PyPI artifacts using multiple execution paths, plus a fake prompt-injection header likely meant to interfere with LLM-based malware triage: socket.dev/blog/mini-sh...
npm accidentally marked a bunch of one-character packages as security holders, including c, i, n, x, several numbers, and even the - package. The registry confirmed it was a tooling bug and said a rollback is underway. socket.dev/blog/npm-too...
📦 @pnpm.io 11.5 adds support for recognizing npm staged publishes after staged approval metadata triggered a false downgrade signal. As npm adds more release paths, registry metadata needs to make it clear how each package version was published. socket.dev/blog/pnpm-11...
📦 @pnpm.io 11.5 adds support for recognizing npm staged publishes after staged approval metadata triggered a false downgrade signal. As npm adds more release paths, registry metadata needs to make it clear how each package version was published. socket.dev/blog/pnpm-11...
Rust is moving toward a formal LLM contribution policy after months of heated internal debate, driven by a wave of low-effort "slop PRs" straining maintainers. The proposal bans LLM authorship but allows private use. socket.dev/blog/rust-mo...
💸 Dept. of Commerce audit: NIST had no strategic plan for the NVD backlog, set an unrealistic deadline, delayed CISA data use, and eroded trust with poor communication. Auditors also found 21,000+ duplicate enrichment activities and ~$200K wasted. socket.dev/blog/federal...
5d
2d
1d
7d
3d
2d
8d
8d
11d
8d
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads w...
socket.dev
Replit is integrating Socket Firewall into its AI-powered development experience to help protect builders from malicious open source packages.
socket.dev
Socket Partners with Replit to Block Malicious Packages in A...
Socket’s first CISO brings deep experience securing high-growth SaaS companies as open source supply chain threats accelerate.
socket.dev
Andrew Becherer Joins Socket as Chief Information Security O...
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.
socket.dev
RubyGems Adds Cooldown Feature to Bundler for Newly Publishe...
Newer packages in this compromise use native extensions and .pth loaders to execute JavaScript stealers in developer environments.
socket.dev
Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformati...
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.
socket.dev
npm Tooling Bug Incorrectly Marks One-Character Packages as ...
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publi...
socket.dev
pnpm 11.5 Adds Support for Recognizing npm Staged Publishes ...
pnpm 11.5 Adds Support for Recognizing npm Staged Publishes ...
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publi...
socket.dev
The Rust project is moving toward formal rules on LLM use in contributions after months of internal debate over maintainer burden, code quality, and c...
socket.dev
Rust Moves to Restrict LLM Use in Contributions After Months...
Federal audit finds NIST lacked a plan to clear the NVD backlog, wasted funds on duplicate work, and delayed use of CISA data.
socket.dev
Federal Audit Finds NIST Wasted Funds With No Plan to Clear ...
Socket
Socket
Socket
Socket
Socket
Socket
Socket
Socket
Socket
Socket