The Socket Threat Research Team continues to track North Koreaβs Contagious Interview operation as it systematically infiltrates the npm ecosystem. socket.dev/blog/north-k... @socket.dev
01.12.2025 12:53 β π 3 π 2 π¬ 1 π 0@feross.bsky.social
π§ββοΈ Mad scientist β’ β¨ Founder + CEO @Socket.dev (http://socket.dev) β’π² Stanford lecturer (http://cs253.stanford.edu) β’ β€οΈ Open source at WebTorrent + StandardJS
The Socket Threat Research Team continues to track North Koreaβs Contagious Interview operation as it systematically infiltrates the npm ecosystem. socket.dev/blog/north-k... @socket.dev
01.12.2025 12:53 β π 3 π 2 π¬ 1 π 0More malicious Chrome extensions.
Stay vigilant!
Glad to hear it!
25.11.2025 19:56 β π 3 π 0 π¬ 0 π 0Update: at time of writing Eleventy core (0.x, 1.x, 2.x, 3.x, 4.x prereleases) and our official plugins are still unaffected.
(Compromised package count was updated to 834 from 533 in the latest @socket.dev update)
There is an ongoing npm security event.
At time of writing, Eleventy core and our official suite of plugins are unaffected.
Ha, thanks. One of those situations where I'm only partially happy to be right. Mostly just glad that we're building something helpful.
25.11.2025 04:22 β π 8 π 0 π¬ 0 π 0*this is fine meme*
24.11.2025 17:38 β π 4 π 1 π¬ 0 π 0π€― The number of affected packages in the Shai-Hulud npm attack has now reached 770. Weβre continuing to investigate and will keep the blog post updated:
socket.dev/blog/shai-hu...
thatβs a scary read tbh
24.11.2025 23:37 β π 5 π 2 π¬ 1 π 0We have updated this list to include more than 500 packages and 700+ affected versions, as well as a technical analysis of the attack. socket.dev/blog/shai-hu....
cc: @campuscodi.risky.biz @typescript.fm @bleepingcomputer.com @theregister.com
Here we go again
24.11.2025 15:01 β π 8 π 1 π¬ 0 π 1Read the full announcement here: socket.dev/blog/introdu...
22.11.2025 00:36 β π 1 π 1 π¬ 0 π 0Webhooks for Alert Changes just dropped π
No more refreshing dashboards. Socket now pushes every new, updated, or cleared alert straight into your workflow in real time.
Perfect way to wrap Launch Week: Ruby reachability, Certified Patches, Bun/vlt, OpenVSXβ¦ and now this β‘οΈ
Read the full announcement here: socket.dev/blog/introdu...
20.11.2025 17:47 β π 1 π 1 π¬ 0 π 0IDE extensions are a silent nightmare.
VS Code extensions get full access to your code and creds, and attackers have already slipped malware into VS Code Marketplace and OpenVSX.
So Socket now scans OpenVSX extensions before they ever hit your machine. πβ‘οΈ
π Big news for JavaScript teams: Socket now supports Bun and vlt in beta.
You no longer have to choose between innovation and security. Commit a bun.lock or vlt-lock.json and Socket gives you full supply chain protection.
Thanks for sharing!
19.11.2025 07:46 β π 1 π 0 π¬ 0 π 0π
19.11.2025 07:46 β π 1 π 0 π¬ 0 π 0Certified Patches are available today in closed beta for enterprise teams (JavaScript/TypeScript).
Want early access? Contact sales@socket.dev or your customer success manager.
Patches live locally in your repo, apply during builds, and require zero workflow changes. No registry proxies. No new infra. Patches belong to you - there's no lock-in.
Pair Certified Patches with Socket Reachability and you get a clear path to zero exploitable CVEs instantly.
Recent supply chain attacks have shown us a hard truth: updating dependencies can sometimes be risky. With Certified Patches, you can now eliminate CVEs instantly without upgrading or pulling in new, unvetted code.
18.11.2025 19:39 β π 1 π 1 π¬ 1 π 0π Day 2 of Socket Launch Week:
Today weβre introducing a major shift in how developers fix vulnerabilities: Socket Certified Patches.
One-click, safe-by-design remediation for vulnerable dependencies.
π¨ New npm malware campaign uncovered: 7 malicious packages use Adspect cloaking and fake CAPTCHAs to hide redirects to #crypto scam sites.
Read the full analysis β socket.dev/blog/npm-mal...
This is a novel technique attackers are using to distribute browser-executed malware through npm.
cc: @campuscodi.risky.biz
π Day Two of Socket Launch Week!
Weβre launching @socket.dev Certified Patchesβa new way to eliminate vulnerabilities instantly without upgrading your package versions or pulling in risky new code.
Tiny, human-reviewed fixes that give teams a clean path to zero exploitable CVEs.
Yes, we support Go in the enterprise version of the firewall. You can reach out to us at sales@socket.dev to get access.
17.11.2025 20:41 β π 0 π 0 π¬ 0 π 0Woo!!!
π«ΆπΌ #socket
7/ Dive in here: socket.dev/blog/reachab...
17.11.2025 18:24 β π 2 π 1 π¬ 0 π 06/ You can try it today:
β’ Precomputed reachability in the Socket Dashboard
β’ Full application reachability via CLI with socket scan create --reach
This is another step toward bringing precise, function-level reachability to every major ecosystem π
5/ Itβs conservative by design: when Ruby gets wild, we donβt guess. We err on the side of safety so real issues never slip through.
17.11.2025 18:24 β π 1 π 1 π¬ 1 π 0