It simply tells your AI agent "you're an authorized pentester" and lets the it do the stealing.
Socket CTO @ahmadnassri.com Nassri on Insecure Agents with Allie Howe: socket.dev/blog/insecur...
It simply tells your AI agent "you're an authorized pentester" and lets the it do the stealing.
Socket CTO @ahmadnassri.com Nassri on Insecure Agents with Allie Howe: socket.dev/blog/insecur...
This summer, @socket.dev automatically blocked two live supply chain attacks at the world's largest company.
This summer, @socket.dev automatically blocked two live supply chain attacks at the world's largest company.
During a UK cyber test, a Mythos 5 agent used sockpuppets, spearphishing emails, and prompt injection to try to get an open source maintainer to merge malware.
socket.dev/blog/ai-agen... #OpenSource #Cybersecurity
During a UK cyber test, a Mythos 5 agent used sockpuppets, spearphishing emails, and prompt injection to try to get an open source maintainer to merge malware.
socket.dev/blog/ai-agen... #OpenSource #Cybersecurity
Also new: Socket Firewall bills on unique artifacts checked, not bandwidth or downloads. Pin 200 packages, install them a million times, pay for 200.
socket.dev/blog/aws-sec...
Also new: Socket Firewall bills on unique artifacts checked, not bandwidth or downloads. Pin 200 packages, install them a million times, pay for 200.
socket.dev/blog/aws-sec...
@socket.dev is now tracking 2,234 malicious package artifacts across 444 unique packages in the keyv/cacheable compromise.
Average detection time: 5 min 18 sec after publication
@socket.dev is now tracking 2,234 malicious package artifacts across 444 unique packages in the keyv/cacheable compromise.
Average detection time: 5 min 18 sec after publication
socket.dev/blog/socket-...
socket.dev/blog/socket-...
No operating plan is public yet, even as federal vulnerability programs face massive backlogs and failures.
socket.dev/blog/white-h...
No operating plan is public yet, even as federal vulnerability programs face massive backlogs and failures.
socket.dev/blog/white-h...
This new package uses prompt-injection-style comments, safety-triggering content, context flooding, and obfuscated JS to probe where scanners refuse, truncate, or miss the code that matters.
socket.dev/blog/npm-pac...
This new package uses prompt-injection-style comments, safety-triggering content, context flooding, and obfuscated JS to probe where scanners refuse, truncate, or miss the code that matters.
socket.dev/blog/npm-pac...
It’s already blocking 8K malicious packages/day across builders on the platform, giving Replit users stronger protection by default at the moment dependencies are introduced.
socket.dev/blog/socket-...
It’s already blocking 8K malicious packages/day across builders on the platform, giving Replit users stronger protection by default at the moment dependencies are introduced.
socket.dev/blog/socket-...
The registry confirmed it was a tooling bug and said a rollback is underway.
socket.dev/blog/npm-too...
The registry confirmed it was a tooling bug and said a rollback is underway.
socket.dev/blog/npm-too...
socket.dev/blog/npm-inv... #NodeJS #JavaScript
socket.dev/blog/npm-inv... #NodeJS #JavaScript
(Maybe we should be SoCket now! ok eeew no)
All I can see on my part is that I've been having an awesome time working on AI and with AI, detection, and what not. Lucky to be part in the right place at the right time :D
bsky.app/profile/fero...
(Maybe we should be SoCket now! ok eeew no)
All I can see on my part is that I've been having an awesome time working on AI and with AI, detection, and what not. Lucky to be part in the right place at the right time :D
bsky.app/profile/fero...
1. Cascading, cross-ecosystem propagation (PyPi ➡️ npmjs ➡️ Packagist)
2. Using a JS runtime (Bun) to infect Python and PHP
3. Impersonates Claude in git commits to hide in plain sight
🧵
1. Cascading, cross-ecosystem propagation (PyPi ➡️ npmjs ➡️ Packagist)
2. Using a JS runtime (Bun) to infect Python and PHP
3. Impersonates Claude in git commits to hide in plain sight
🧵
These cloned extensions initially appear benign, then later become malware delivery vehicles through normal updates.
socket.dev/blog/73-open...
These cloned extensions initially appear benign, then later become malware delivery vehicles through normal updates.
socket.dev/blog/73-open...
The malicious versions replicate TeamPCP-style Canister Worm tradecraft, including secret theft, exfiltration, and self-propagation.
socket.dev/blog/namaste...
The malicious versions replicate TeamPCP-style Canister Worm tradecraft, including secret theft, exfiltration, and self-propagation.
socket.dev/blog/namaste...
A hypocritical corporate strategy of extracting immense financial value from unpaid, open-source labor, only to later declare OSS "dead" or untrustworthy to justify forking, rebuilding, and rebundling that exact same software as a premium, "safe" product.
Let’s talk goosenomics for a minute. → socket.dev/blog/dont-ki...
A hypocritical corporate strategy of extracting immense financial value from unpaid, open-source labor, only to later declare OSS "dead" or untrustworthy to justify forking, rebuilding, and rebundling that exact same software as a premium, "safe" product.
Another tool for securing your build pipeline - DHI are free and open source: socket.dev/blog/socket-...
Stolen creds poison packages, poisoned packages steal creds, and the loop keeps accelerating.
Docker’s CISO breaks down what’s actually happening & what teams can do to reduce risk: https://bit.ly/3NMjF8K
Another tool for securing your build pipeline - DHI are free and open source: socket.dev/blog/socket-...
Not for crypto. For write access to packages downloaded trillions of times a year.
Lodash. Fastify. axios. mocha. Node.js core. Even @feross.bsky.social and several @socket.dev engineers!
socket.dev/blog/attacke...
Not for crypto. For write access to packages downloaded trillions of times a year.
Lodash. Fastify. axios. mocha. Node.js core. Even @feross.bsky.social and several @socket.dev engineers!
socket.dev/blog/attacke...
Deep dive into the messy reality of modern dependency resolution → socket.dev/blog/hidden-...
Deep dive into the messy reality of modern dependency resolution → socket.dev/blog/hidden-...
Semver + transitive deps + runtime installs = hidden blast radius.
If you only checked your project’s lockfile, you may still not know.
socket.dev/blog/hidden-... #nodejs #javascript
1. Individually "install" packages you want to use, within a specified directory: (e.g. $HOME/mcp) creating a lockfile
2. Add: "--include-workspace-root --workspace $HOME/mcp --no --offline" to EVERY npx call
Semver + transitive deps + runtime installs = hidden blast radius.
If you only checked your project’s lockfile, you may still not know.
socket.dev/blog/hidden-... #nodejs #javascript
1. Individually "install" packages you want to use, within a specified directory: (e.g. $HOME/mcp) creating a lockfile
2. Add: "--include-workspace-root --workspace $HOME/mcp --no --offline" to EVERY npx call
npm i -g sfw
sfw npm install
sfw pnpm install
sfw yarn install
sfw cargo fetch
sfw uv pip install
socket.dev/blog/introdu...
npm i -g sfw
sfw npm install
sfw pnpm install
sfw yarn install
sfw cargo fetch
sfw uv pip install
socket.dev/blog/introdu...