You no longer have to choose between innovation and security. Commit a bun.lock or vlt-lock.json and Socket gives you full supply chain protection.
cc: @campuscodi.risky.biz @bleepingcomputer.com @coindesk.com @web3isgoinggreat.com
Full investigation → socket.dev/blog/malicio... #crypto
cc: @campuscodi.risky.biz @bleepingcomputer.com @coindesk.com @web3isgoinggreat.com
What that means for disclosure, patching, and the maintainers at the heart of open source security.
socket.dev/blog/the-nex... #oss
Full analysis: socket.dev/blog/glasswo...
Many thanks to @jddalton.bsky.social, @jordan.har.band, and @ulisesgascon.com for their insights on maintaining Lodash and all the hard work put into reviving the project. 💚
We spoke with maintainers about its first security release in years — and why sunsetting it was never a real option.
socket.dev/blog/inside-...
Many thanks to @jddalton.bsky.social, @jordan.har.band, and @ulisesgascon.com for their insights on maintaining Lodash and all the hard work put into reviving the project. 💚
Full Research → socket.dev/blog/malicio...
socket.dev/blog/curl-sh...
Huge thanks to @joyeecheung.bsky.social and the many contributors who made this possible! 🙏
socket.dev/blog/node-js...
More details → socket.dev/blog/introdu...
Huge thanks to @joyeecheung.bsky.social and the many contributors who made this possible! 🙏
socket.dev/blog/node-js...
Huge thanks to @joyeecheung.bsky.social and the many contributors who made this possible! 🙏
socket.dev/blog/node-js...
@campuscodi.risky.biz @decrypt.co @darkreading.bsky.social @coindesk.com
The typosquat reuses SymPy’s branding and pulls ELF payloads at runtime.
Full analysis: socket.dev/blog/pypi-pa... #Python
@campuscodi.risky.biz @decrypt.co @darkreading.bsky.social @coindesk.com
📖 Read more: www.helpnetsecurity.com/2026/01/19/f...
#cybersecurity #cybersecuritynews #remoteaccesstrojan #socialengineering @huntress.com @socket.dev
📖 Read more: www.helpnetsecurity.com/2026/01/19/f...
#cybersecurity #cybersecuritynews #remoteaccesstrojan #socialengineering @huntress.com @socket.dev
Temporal is the modern replacement for the old JS Date API ✨
socket.dev/blog/tempora... h/t @robpalmer.bsky.social
Temporal is the modern replacement for the old JS Date API ✨
Check out the full episode →
socket.dev/blog/insecur...
Check out the full episode →
socket.dev/blog/insecur...
Full story → socket.dev/blog/tailwin... #OSS #CSS
Read it here: socket.dev/blog/npm-to-...
Read it here: socket.dev/blog/npm-to-...
It follows a year of supply chain attacks & a rocky shift away from classic tokens over the past month that left many maintainers struggling.
socket.dev/blog/npm-to-... #NodeJS cc: @campuscodi.risky.biz
Dependabot opens a PR. Socket flags it as malicious.
Socket CEO @feross.bsky.social discusses dependency risk and update timing, on @softwaredaily.bsky.social.
Full episode → socket.dev/blog/softwar...
Dependabot opens a PR. Socket flags it as malicious.
Socket CEO @feross.bsky.social discusses dependency risk and update timing, on @softwaredaily.bsky.social.
Full episode → socket.dev/blog/softwar...
“I put this code online as a gift to the world. I didn’t promise it would never have a defect.”
Full episode → socket.dev/blog/softwar... #OpenSource
“I put this code online as a gift to the world. I didn’t promise it would never have a defect.”
Full episode → socket.dev/blog/softwar... #OpenSource
socket.dev/blog/spearph...
socket.dev/blog/spearph...
cc: @campuscodi.risky.biz @cisoseries.bsky.social @zackwhittaker.com
socket.dev/blog/spearph...
cc: @campuscodi.risky.biz @cisoseries.bsky.social @zackwhittaker.com
Full research → socket.dev/blog/malicio...
Full research → socket.dev/blog/malicio...
Full research → socket.dev/blog/malicio...
This fake “VPN” ran for years and charged users for the privilege of silently intercepting their traffic.
cc: @campuscodi.risky.biz @zackwhittaker.com @cisoseries.bsky.social
Full research → socket.dev/blog/malicio...
This fake “VPN” ran for years and charged users for the privilege of silently intercepting their traffic.
cc: @campuscodi.risky.biz @zackwhittaker.com @cisoseries.bsky.social