Developers using the popular binary-parser library for Node.js are being urged to update their dependencies immediately following...
npm
Developers relying on orval to generate type-safe clients from OpenAPI specifications are being urged to update immediately...
The open-source ecosystem has once again been weaponized, this time targeting developers working with cryptocurrency libraries. In...
A new investigation by Koi Security has exposed a highly sophisticated supply chain attack lurking in the...
A new investigation by The Socket Threat Research Team has uncovered a sophisticated spear-phishing operation that has...
A high-severity vulnerability has been uncovered in systeminformation, a massively popular Node.js library used by millions of...
CERT/CC has issued a warning about a high-impact cryptographic vulnerability in the Forge JavaScript library — also...
The Socket Threat Research Team has uncovered a highly coordinated malware campaign operating across seven npm packages,...
In one of the largest open-source supply chain incidents ever recorded, Amazon Inspector security researchers have uncovered...
Researchers at Datadog Security Research have uncovered a major supply-chain compromise in the npm ecosystem involving 17...
Koi Security has uncovered a massive supply-chain campaign dubbed PhantomRaven, which has silently infected the npm ecosystem...
The Socket Threat Research Team has uncovered an extensive supply chain attack targeting the npm ecosystem, involving...
The Socket Threat Research Team has uncovered a growing trend among malicious package developers: leveraging Discord webhooks...
The Socket Threat Research Team has sounded the alarm on an escalating wave of malicious npm activity...
Socket’s Threat Research Team has uncovered a massive supply-chain abuse campaign leveraging npm’s public registry and unpkg.com’s...
The Socket Threat Research Team has uncovered a new malware campaign hiding inside an npm package called...
The malicious supply chain campaign dubbed “Shai-Hulud” has struck again, this time compromising multiple npm packages published...
The Socket Research Team has uncovered a large-scale supply chain attack on the npm ecosystem, with more...
Socket has detected a large-scale supply chain attack in progress targeting the npm ecosystem. The account of...
Researchers from ReversingLabs have discovered two malicious npm packages leveraging Ethereum smart contracts to conceal and deliver...
Researchers from Socket’s Threat Research Team have uncovered a dangerous npm package, nodejs-smtp, that impersonates the widely...
The StepSecurity research team has issued a warning about a large-scale supply chain attack involving the popular...