home.social
  1. 🚨 Socket detected malicious activity in newly published versions of node-ipc, an npm package with 822K weekly downloads.

    Affected versions:
    [email protected]
    [email protected]
    [email protected]

    Socket’s AI scanner flagged the malware within ~3 minutes of publication.

    Early analysis shows obfuscated stealer/backdoor behavior, including host fingerprinting, local file enumeration, payload wrapping, and attempted exfiltration.

    socket.dev/blog/node-ipc-packa

  2. 🐘 @packagist is urging projects to update Composer after a GitHub token format change caused some GitHub Actions tokens to be exposed in CI logs.

    GitHub has rolled back the token change for now, but affected projects still need to update Composer.

    socket.dev/blog/packagist-urge

  3. 🚨 We detected malicious client packages published to npm and PyPI after a maintainer account compromise, enabling wallet theft and remote code execution.

    Full investigation → socket.dev/blog/malicious-dydx

  4. 🚨 New Research: Threat actors compromised four extensions, pushed malicious updates that load encrypted malware, evade Russian locales, and fetch C2 instructions via memos, leading to macOS credential and wallet theft.

    Full analysis: socket.dev/blog/glassworm-load

  5. 🚨 New from the Socket Threat Research Team: 5 coordinated Chrome extensions hijack sessions and block security controls in enterprise HR and ERP platforms like Workday and NetSuite.

    Full report → socket.dev/blog/5-malicious-ch

  6. 🚨 New research: A malicious Chrome Web Store extension is stealing newly created API keys and exfiltrating them to a Telegram bot, enabling full account takeover with trading and withdrawal rights.

    Details → socket.dev/blog/malicious-chro

  7. 🚨 New threat research: An impostor package typosquatted a popular .NET tracing library and its author, using homoglyph tricks to blend in, then exfiltrated wallet JSON and passwords to a Russian IP address.

    Full report →
    socket.dev/blog/malicious-nuge

  8. 🚨 Socket’s Threat Research Team uncovered a malicious Chrome extension posing as an wallet. It steals seed phrases by encoding them into transactions and leaks them on-chain - no C2 needed.

    socket.dev/blog/malicious-chro

  9. 🚨 The Socket Research team has uncovered a malicious npm package targeting developers using tools in their development environments: socket.dev/blog/malicious-npm-