Veracode Threat Research has released an update on an ongoing North Korean cyber-espionage campaign that is actively...
npm
In a recently expose, Sonatype reveals a covert cyberespionage campaign orchestrated by the North Korea-linked Lazarus Group,...
The lightweight JavaScript utility library is is a widely popular project on the NPM platform, boasting over...
Socket’s Threat Research Team has discovered that at least 10 malicious packages were published to npm from...
The Socket Threat Research Team has uncovered a coordinated surveillance malware campaign hidden in four open-source packages—three...
A deceptive and highly targeted phishing campaign has successfully compromised several popular npm packages, including eslint-config-prettier, eslint-plugin-prettier,...
In a revelation for the JavaScript ecosystem, Socket’s Threat Research Team has uncovered the widespread proliferation of...
A new chapter in the ongoing Contagious Interview campaign has emerged, as the Socket Threat Research Team...
In a detailed expose, the Socket Threat Research Team has uncovered an ongoing and highly targeted supply...
Two high-impact security advisories have been released for the pbkdf2 npm package—an essential utility in the JavaScript...
A tool named PoCGen is revolutionizing how the security community generates Proof-of-Concept (PoC) exploits for vulnerabilities in...
The Socket Threat Research Team has disclosed two dangerous npm packages that masquerade as helpful developer tools—but...
Socket Threat Research Team has uncovered a new threat lurking within the JavaScript ecosystem: four malicious npm...
In a recent revelation, Socket’s Threat Research Team has uncovered a stealthy npm supply chain attack leveraging...
Socket’s Threat Research Team has uncovered an active and expanding malware campaign in the npm ecosystem. More...
In a disturbing development for the JavaScript community, Socket’s Threat Research Team has uncovered a stealthy and...
Socket’s Threat Research Team has uncovered a dangerous new threat lurking in the npm ecosystem: a malicious...
The Socket Threat Research Team has exposed three malicious open-source packages masquerading as developer tools — designed...
A new supply chain attack has been uncovered by Socket’s Threat Research Team, targeting developers who create...
A malicious npm package, disguised as a merchant integration for the Advcash payment platform, has been discovered...