Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. 👀 @npm_malware

Filter
Exclude
Time range
-
Minimum likes
Shai-Hulud showed how aggressively a malicious package can harvest developer tokens. Now agents install packages on their own. We're demoing how to validate what your agents pull in at Agent Baseline Demo Night in NYC w/ @KeycardAI & @braintrust. Our CTO @AhmadNassri is on the panel. RSVP: luma.com/keycard-rg1c
3
3
5
725
Socket retweeted
Open source’s next chapter might be a thousand slightly different versions of the same software. socket.dev/blog/oj-vite-rust
3
4
14
2,756
Socket retweeted
Compromised MemOS packages on npm and PyPI spread cross-platform malware that steals developer credentials and may use stolen tokens to compromise more packages, @SocketSecurity reported. #cybersecurity #CISO #infosec bit.ly/4hdOXRQ
1
1
5
2,528
Socket retweeted
Compromised MemOS packages on npm and PyPI spread cross-platform malware that steals developer credentials and may use stolen tokens to compromise more packages, @SocketSecurity reported. #cybersecurity #CISO #infosec bit.ly/4hdOXRQ
1
2
4
2,306
Maintainers spend countless hours keeping the open source projects we all rely on secure. Too often, that work is unpaid. Socket is proud to join @openjsf's new Security Stewardship Program to help fund the researchers and maintainers protecting Node.js. socket.dev/blog/openjs-nodej…
3
14
1,952
Socket retweeted
Absolutely crazy that these two GitHub Actions which were quarantined could be reactivated with the malware still armed. Many of the these workflows run on a cron without any true repository activity trigging them.
3
7
2,037
‼️ Mini Shai-Hulud came back without a new attacker update. Two compromised GitHub Actions became reachable again while their tags still pointed to malicious commits, letting downstream workflows resume executing the credential stealer. 🔗 Here's how the attack reactivated: thehackernews.com/2026/09/co…
7
20
78
38,491
Socket retweeted
Compromised MemOS packages on npm and PyPI spread cross-platform malware that steals developer credentials and may use stolen tokens to compromise more packages, @SocketSecurity reported. #cybersecurity #CISO #infosec bit.ly/4hdOXRQ
2
3
6
2,542
Socket retweeted
Absolutely crazy that these two GitHub Actions which were quarantined could be reactivated with the malware still armed. Many of the these workflows run on a cron without any true repository activity trigging them.
🚨 Two GitHub Actions compromised in May’s Mini Shai-Hulud campaign are running malware again. The repositories were re-enabled with malicious release tags intact, putting thousands of downstream repositories at risk. socket.dev/blog/mini-shai-hu…
5
15
7,272
Bottom line: You can’t control when a compromised repository comes back online, but you can control what your workflows run. Pin third-party GitHub Actions to a known-clean commit SHA. That would have stopped this malicious code from running in both May and September.
1
8
852
🚨 Two GitHub Actions compromised in May’s Mini Shai-Hulud campaign are running malware again. The repositories were re-enabled with malicious release tags intact, putting thousands of downstream repositories at risk. socket.dev/blog/mini-shai-hu…
4
8
37
9,642
Socket retweeted
Compromised MemTensor packages hit npm and PyPI today. Check our analysis for affected versions, cleanup guidance, and updates. socket.dev/blog/memtensor-co…
4
10
2,102
Socket retweeted
Pretty wild how this extension will piece together it's code from a C2 server.
Socket researchers found a malicious Firefox extension that poses as a PDF identity verifier to hijack Google accounts. It fetches its payload after installation, steals Google session cookies, and can silently reset the victim’s password. socket.dev/blog/firefox-goog…
1
4
32
7,008
Socket researchers found a malicious Firefox extension that poses as a PDF identity verifier to hijack Google accounts. It fetches its payload after installation, steals Google session cookies, and can silently reset the victim’s password. socket.dev/blog/firefox-goog…
1
7
21
10,437
🚨 MemTensor’s npm and PyPI packages have been compromised. Four malicious releases, including the latest version on both registries, drop cross-platform Go binaries that steal npm, PyPI, GitHub, AWS, SSH and other developer secrets. socket.dev/blog/memtensor-co…
6
10
2,660
Socket retweeted
Lovable rewrote Vite’s dev server in Rust. OJ uses ~75% less memory, and Lovable now provisions sandboxes in 3 seconds instead of 14.5. Evan You thinks AI may make these tailored rewrites more common to where everyone "maintains their own slop fork.” socket.dev/blog/oj-vite-rust
5
14
2,767