π¨ Critical RCE in @nestjs/devtools-integration:
A broken sandbox + CSRF lets any website trigger code execution on your dev machine if the dev server is running.
Full disclosure: socket.dev/blog/nestjs-...
@socket.dev.bsky.social
Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. https://socket.dev
π¨ Critical RCE in @nestjs/devtools-integration:
A broken sandbox + CSRF lets any website trigger code execution on your dev machine if the dev server is running.
Full disclosure: socket.dev/blog/nestjs-...
π Day 5 of Launch Week!
We're introducing License Overlays: fine-tune Socketβs license detection to match your teamβs policy.
Handle edge cases, preserve attribution, and reduce false positives with precision.
socket.dev/blog/introdu...
π Day 4 of Launch Week: Introducing Rust support in Socket!
Search any crate on socket.dev β no login required.
Enterprise users get early access to experimental SBOM generation & full supply chain protection.
π¦ More Details β socket.dev/blog/introdu... #RustLang cc: @thisweekinrust.bsky.social
β‘οΈ Instant Analysis: Results are precomputed and cached for popular dependencies, so they're available immediately.
π§ββοΈ Zero-Overhead: No additional scans, no agents, no performance impact.
π Privacy-Preserving: We never need access to your source code.
Available now β
socket.dev/blog/announc...
π Day 3 of Socket Launch Week: We're launching Precomputed Reachability Analysis!
Socket takes a radically different approach, using just your manifest files (package-lock.json, requirements.txt, pom.xml, etc.) to slash false positives by flagging up to 80% of CVEs as irrelevant.
Day 2 of Socket Launch Week: DOUBLE LAUNCH π
Browser extensions are a growing attack surface for nearly every organization.
Today, weβre launching an experimental release of Chrome extension scanning to detect malware and risky updates.
π§© Learn more β socket.dev/blog/socket-...
π Day 2 of Socket Launch Week: Introducing Socket MCP for Claude Desktop!
Add one-click dependency security scanning to your Claude conversations. No CLI, no configuration files: just install and ask #Claude to check your dependencies.
Try it now β socket.dev/blog/introdu...
π Weβre kicking off a big launch week at Socket ahead of Black Hat, dropping a new feature every day this week!
Day 1: Scala & Kotlin Support is now in beta!β¨AI-powered supply chain threat detection for JVM projects with fast, accurate scans.
socket.dev/blog/introdu... #Java
npm package `is` hijacked in expanding supply chain attack
@sarahgooding.bsky.social @socket.dev
socket.dev/blog/npm-is-...
#ECMAScript #JavaScript
Check out our case study to learn how JupiterOne partnered with Socket to:
β‘οΈ Integrate policy-driven security into CI/CD
β‘οΈ Cut false positives with reachability analysis
β‘οΈ Achieve audit-ready compliance automatically
β‘οΈ Scale security without additional overhead
socket.dev/case-study/j...
Vibe coding with LLMs is making developers faster, but also creating new attack surfaces. Socket CEO @feross.bsky.social talks with Joel de la Garza of a16z about the future of AI-assisted software and supply chain security.
ποΈ Check out the full episode: socket.dev/blog/ai-a16z...
Not pretty, not Windows-only: npm phishing attack laces popular packages with malware
24.07.2025 10:06 β π 7 π 5 π¬ 0 π 0π¨ Supply chain attack alert: A threat actor gained access to Toptal's GitHub org, making 73 repos public and injecting malicious payloads into 10+ npm packages.
Full research: socket.dev/blog/toptal-... #NodeJS #JavaScript
Check out our case study to learn how JupiterOne partnered with Socket to:
β‘οΈ Integrate policy-driven security into CI/CD
β‘οΈ Cut false positives with reachability analysis
β‘οΈ Achieve audit-ready compliance automatically
β‘οΈ Scale security without additional overhead
socket.dev/case-study/j...
"We tried a variety of different solutions, but Socket turned out to be the most cost-effective and efficient, replacing all the others."
- Kenneth Kaye, Lead Security Engineer at JupiterOne
π¨ New Threat Research: We uncovered 4 malicious packages (3 on npm, 1 on PyPI) with 56,000+ downloads, all delivering surveillance malware capable of keylogging, screen capture, and webcam access.
Hereβs what we found: socket.dev/blog/surveil... #NodeJS #JavaScript #Python
π¨ Attackers have hijacked the npm 'is' package (~2.8M weekly downloads), adding a malicious JS loader. This compromise is linked to the recent npm phishing campaign. Read our update on this ongoing supply chain attack: socket.dev/blog/npm-is-... #NodeJS #JavaScript
22.07.2025 20:09 β π 11 π 7 π¬ 1 π 0π¨ Attackers have hijacked the npm 'is' package (~2.8M weekly downloads), adding a malicious JS loader. This compromise is linked to the recent npm phishing campaign. Read our update on this ongoing supply chain attack: socket.dev/blog/npm-is-... #NodeJS #JavaScript
22.07.2025 20:09 β π 11 π 7 π¬ 1 π 0π¨ A critical vulnerability in the widely used npm form-data package could allow HTTP Parameter Pollution, potentially impacting millions of projects. The package sees 100M+ downloads weekly.
Details β socket.dev/blog/critica... #NodeJS #JavaScript
"Hours after we reported on the npm phishing campaign using the typosquatted npnjs com site, weβre now seeing the first major fallout: popular npm packages, including eslint-config-prettier and eslint-plugin-prettier, were compromised" #eslint #npm #nodejs
socket.dev/blog/npm-phi...
Bun 1.2.19 introduces isolated installs for monorepos, smarter package management, and 5x faster Bun.sql. π Congrats to @jarredsumner.com and all the @bun.sh contributors: socket.dev/blog/bun-1-2... #NodeJS
22.07.2025 02:43 β π 1 π 1 π¬ 0 π 0Be aware and don't fall for this βοΈ
19.07.2025 08:21 β π 0 π 1 π¬ 0 π 0Thanks for that feedback! I'll share it with the team. The AI package summary tab there could use some improvements, especially for packages where there is no README. We're looking into it, and thank you for reporting the issue. π
19.07.2025 02:29 β π 1 π 0 π¬ 0 π 0π¨ Active supply chain attack on npm:
Multiple Prettier tooling packages were compromised through the phishing campaign we published about just hours ago. Watch out for more compromised accounts and malicious packages.
Follow-up: socket.dev/blog/npm-phi... #nodejs #npm
π¨ npm phishing alert!
Attackers are sending emails from spoofed support@npmjs.org addresses linking to a typosquatted clone site (npnjs.com) to steal credentials. This attack is designed to hijack npm accounts. Careful with those email links: socket.dev/blog/npm-phi... #nodejs #JavaScript
βοΈ Knip, the popular open source tool for finding unused code and dependencies, just hit 500 releases with v5.62.0. This release features #TypeScript config refinements and plugin updates. Congrats to @larskappert.nl & all the Knip contributors! π socket.dev/blog/knip-hi... #JavaScript
18.07.2025 17:59 β π 8 π 0 π¬ 1 π 0EUβs Cyber Resilience Act isnβt fully in effect yet but #OSS maintainers are already bracing for compliance requests. cURL is among the first to receive one (from a Fortune 500 company using a 2 year old version.)
What happens when companies treat volunteers like vendors? socket.dev/blog/oss-mai...
EUβs Cyber Resilience Act isnβt fully in effect yet but #OSS maintainers are already bracing for compliance requests. cURL is among the first to receive one (from a Fortune 500 company using a 2 year old version.)
What happens when companies treat volunteers like vendors? socket.dev/blog/oss-mai...
π¦ Rust is the latest open source ecosystem to adopt Trusted Publishing, joining PyPI and RubyGems in moving away from long-lived API tokens.
π¦ Crates can now be published using short-lived credentials from trusted CI workflows.
socket.dev/blog/crates-... #RustLang #OpenSource