Researchers from Socket’s Threat Research Team have uncovered a dangerous npm package, nodejs-smtp, that impersonates the widely...
supply chain attack
Trend Micro researchers have detailed a sophisticated cyber-espionage operation, dubbed TAOTH, which leverages hijacked software updates and...
ReversingLabs researchers have uncovered a dangerous loophole in the Visual Studio Code (VS Code) Marketplace that allows...
The StepSecurity research team has issued a warning about a large-scale supply chain attack involving the popular...
The open-source ecosystem has once again been exploited to distribute malicious software. Socket’s Threat Research Team has...
Kudelski Security has published a detailed write-up of a critical vulnerability discovered in CodeRabbit, the most installed...
Zscaler’s ThreatLabz team has issued a warning after uncovering a malicious Python package on the Python Package...
The Python Package Index (PyPI) is taking a significant step toward securing the open-source software supply chain...
The Python Package Index (PyPI) has announced a set of new upload restrictions aimed at protecting Python...
Socket’s Threat Research Team has revealed a long-running supply chain attack in the RubyGems ecosystem, where a...
GitLab’s Vulnerability Research team has exposed a sophisticated cryptocurrency theft campaign targeting the Bittensor decentralized AI network...
Socket’s Threat Research Team has uncovered an alarming wave of malicious Go packages—some still live on GitHub—designed...
Socket’s Threat Research Team has uncovered two malicious npm packages—naya-flore and nvlore-hsc—designed to target developers building WhatsApp...
A critical vulnerability—CVE-2025-54594 (CVSS 9.1)—has been identified in the React Native Bottom Tabs project, exposing the repository...
Veracode Threat Research has released an update on an ongoing North Korean cyber-espionage campaign that is actively...
WithSecure has uncovered a stealthy campaign using legitimate Remote Monitoring and Management (RMM) tools embedded in PDF...
A critical command injection vulnerability has been disclosed in the widely used GitHub Action tj-actions/branch-names, affecting over...
The lightweight JavaScript utility library is is a widely popular project on the NPM platform, boasting over...
Socket’s Threat Research Team has discovered that at least 10 malicious packages were published to npm from...
The Socket Threat Research Team has uncovered a coordinated surveillance malware campaign hidden in four open-source packages—three...