//
sign in
Profile
by @danabra.mov
Profile
by @dansshadow.bsky.social
Profile
by @jimpick.com
AviHandle
by @danabra.mov
AviHandle
by @dansshadow.bsky.social
AviHandle
by @katherine.computer
EventsList
by @katherine.computer
ProfileHeader
by @dansshadow.bsky.social
ProfileHeader
by @danabra.mov
ProfileMedia
by @danabra.mov
ProfilePlays
by @danabra.mov
ProfilePosts
by @danabra.mov
ProfilePosts
by @dansshadow.bsky.social
ProfileReplies
by @danabra.mov
Record
by @atsui.org
Skircle
by @danabra.mov
StreamPlacePlaylist
by @katherine.computer
+ new component
Profile
Loading...
Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. https://socket.dev
Socket









Loading...
🚨 Mini Shai-Hulud/Miasma has now spread to PyPI. Socket found 37 malicious artifacts across 19 PyPI packages. The packages abuse #Python .pth startup behavior to launch a Bun-powered credential stealer targeting developer, cloud, and CI/CD secrets. socket.dev/blog/shai-hu...
🧩 New Research: 152 Chrome "live wallpaper" extensions hid ad tracking behind false privacy disclosures and faked Google search traffic to support ad monetization. The network spanned 38 publisher accounts, 3 backend brands, and ~105K installs. socket.dev/blog/152-chr...
Mini Shai-Hulud/Miasma/Hades is now targeting bioinformatics and MCP developers in a newer PyPI wave. We found 23 newly compromised PyPI artifacts using multiple execution paths, plus a fake prompt-injection header likely meant to interfere with LLM-based malware triage: socket.dev/blog/mini-sh...
Big news for Socket: Andrew Becherer is joining as our first CISO. He brings deep experience leading security at high-growth SaaS companies, and will strengthen the security program behind the infrastructure we operate and the open source ecosystem we protect. socket.dev/blog/andrew-...
npm accidentally marked a bunch of one-character packages as security holders, including c, i, n, x, several numbers, and even the - package. The registry confirmed it was a tooling bug and said a rollback is underway. socket.dev/blog/npm-too...
RubyGems 4.0.13 adds a cooldown feature to Bundler for newly published gems. The opt-in setting lets projects delay dependency resolution for new gem versions, reducing exposure during the short window when malicious releases often spread fastest. socket.dev/blog/rubygem...
📦 @pnpm.io 11.5 adds support for recognizing npm staged publishes after staged approval metadata triggered a false downgrade signal. As npm adds more release paths, registry metadata needs to make it clear how each package version was published. socket.dev/blog/pnpm-11...
📦 @pnpm.io 11.5 adds support for recognizing npm staged publishes after staged approval metadata triggered a false downgrade signal. As npm adds more release paths, registry metadata needs to make it clear how each package version was published. socket.dev/blog/pnpm-11...
💸 Dept. of Commerce audit: NIST had no strategic plan for the NVD backlog, set an unrealistic deadline, delayed CISA data use, and eroded trust with poor communication. Auditors also found 21,000+ duplicate enrichment activities and ~$200K wasted. socket.dev/blog/federal...
🔥 Socket Firewall is now built into Replit's AI-powered development experience. It’s already blocking 8K malicious packages/day across builders on the platform, giving Replit users stronger protection by default at the moment dependencies are introduced. socket.dev/blog/socket-...
5d
1h
4d
1d
3d
7d
8d
8d
9d
2d
Socket found 37 malicious PyPI wheels that abuse Python startup hooks to launch a Bun-powered credential stealer tied to Mini Shai-Hulud/Miasma.
socket.dev
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads w...
Newer packages in this compromise use native extensions and .pth loaders to execute JavaScript stealers in developer environments.
socket.dev
Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformati...
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.
socket.dev
RubyGems Adds Cooldown Feature to Bundler for Newly Publishe...
Socket’s first CISO brings deep experience securing high-growth SaaS companies as open source supply chain threats accelerate.
socket.dev
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.
socket.dev
Andrew Becherer Joins Socket as Chief Information Security O...
npm Tooling Bug Incorrectly Marks One-Character Packages as ...
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publi...
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publi...
socket.dev
socket.dev
pnpm 11.5 Adds Support for Recognizing npm Staged Publishes ...
pnpm 11.5 Adds Support for Recognizing npm Staged Publishes ...
Federal Audit Finds NIST Wasted Funds With No Plan to Clear ...
Federal audit finds NIST lacked a plan to clear the NVD backlog, wasted funds on duplicate work, and delayed use of CISA data.
socket.dev
Replit is integrating Socket Firewall into its AI-powered development experience to help protect builders from malicious open source packages.
socket.dev
Socket Partners with Replit to Block Malicious Packages in A...
Socket
Socket
Socket
Socket
Socket
Socket
Socket
Socket
Socket
Socket
A network of 152 Chrome live wallpaper extensions hid ad tracking and made extension-driven traffic look like Google search clicks.
socket.dev
152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fak...