Socket’s Threat Research Team has discovered that at least 10 malicious packages were published to npm from...
npm
The Socket Threat Research Team has uncovered a coordinated surveillance malware campaign hidden in four open-source packages—three...
A deceptive and highly targeted phishing campaign has successfully compromised several popular npm packages, including eslint-config-prettier, eslint-plugin-prettier,...
In a revelation for the JavaScript ecosystem, Socket’s Threat Research Team has uncovered the widespread proliferation of...
A new chapter in the ongoing Contagious Interview campaign has emerged, as the Socket Threat Research Team...
In a detailed expose, the Socket Threat Research Team has uncovered an ongoing and highly targeted supply...
Two high-impact security advisories have been released for the pbkdf2 npm package—an essential utility in the JavaScript...
A tool named PoCGen is revolutionizing how the security community generates Proof-of-Concept (PoC) exploits for vulnerabilities in...
The Socket Threat Research Team has disclosed two dangerous npm packages that masquerade as helpful developer tools—but...
Socket Threat Research Team has uncovered a new threat lurking within the JavaScript ecosystem: four malicious npm...
In a recent revelation, Socket’s Threat Research Team has uncovered a stealthy npm supply chain attack leveraging...
Socket’s Threat Research Team has uncovered an active and expanding malware campaign in the npm ecosystem. More...
In a disturbing development for the JavaScript community, Socket’s Threat Research Team has uncovered a stealthy and...
Socket’s Threat Research Team has uncovered a dangerous new threat lurking in the npm ecosystem: a malicious...
The Socket Threat Research Team has exposed three malicious open-source packages masquerading as developer tools — designed...
A new supply chain attack has been uncovered by Socket’s Threat Research Team, targeting developers who create...
A malicious npm package, disguised as a merchant integration for the Advcash payment platform, has been discovered...
A recent report from FortiGuard Labs has uncovered a series of malicious NPM packages designed to steal...
A recent report by ReversingLabs (RL) has uncovered malicious packages on the npm repository that employ sophisticated...
Cybersecurity researchers at Socket have uncovered a new supply chain attack orchestrated by Lazarus Group, the notorious...
Researchers at Socket have uncovered a series of malicious campaigns exploiting Out-of-Band Application Security Testing (OAST) techniques....
Researchers from ReversingLabs have highlighted a malicious campaign that bridges two critical ecosystems: Visual Studio Code (VSCode)...