Socketβs Threat Research Team has discovered that at least 10 malicious packages were published to npm from...
npm
The Socket Threat Research Team has uncovered a coordinated surveillance malware campaign hidden in four open-source packagesβthree...
A deceptive and highly targeted phishing campaign has successfully compromised several popular npm packages, including eslint-config-prettier, eslint-plugin-prettier,...
In a revelation for the JavaScript ecosystem, Socketβs Threat Research Team has uncovered the widespread proliferation of...
A new chapter in the ongoing Contagious Interview campaign has emerged, as the Socket Threat Research Team...
In a detailed expose, the Socket Threat Research Team has uncovered an ongoing and highly targeted supply...
Two high-impact security advisories have been released for the pbkdf2 npm packageβan essential utility in the JavaScript...
A tool named PoCGen is revolutionizing how the security community generates Proof-of-Concept (PoC) exploits for vulnerabilities in...
The Socket Threat Research Team has disclosed two dangerous npm packages that masquerade as helpful developer toolsβbut...
Socket Threat Research Team has uncovered a new threat lurking within the JavaScript ecosystem: four malicious npm...
In a recent revelation, Socketβs Threat Research Team has uncovered a stealthy npm supply chain attack leveraging...
Socketβs Threat Research Team has uncovered an active and expanding malware campaign in the npm ecosystem. More...
In a disturbing development for the JavaScript community, Socketβs Threat Research Team has uncovered a stealthy and...
Socketβs Threat Research Team has uncovered a dangerous new threat lurking in the npm ecosystem: a malicious...
The Socket Threat Research Team has exposed three malicious open-source packages masquerading as developer tools β designed...
A new supply chain attack has been uncovered by Socket’s Threat Research Team, targeting developers who create...
A malicious npm package, disguised as a merchant integration for the Advcash payment platform, has been discovered...
A recent report from FortiGuard Labs has uncovered a series of malicious NPM packages designed to steal...
A recent report by ReversingLabs (RL) has uncovered malicious packages on the npm repository that employ sophisticated...
Cybersecurity researchers at Socket have uncovered a new supply chain attack orchestrated by Lazarus Group, the notorious...