A popular bioinformatics tool became the latest lure in a software supply chain attack, as threat actors...
Typosquatting
A relentless state-sponsored campaign by North Korean threat actors is aggressively targeting blockchain and Web3 developers by...
HelixGuard researchers have uncovered a malicious Python package uploaded to PyPI that impersonates the widely used “pyspellchecker”...
Researchers at Palo Alto Networks Unit 42 have uncovered two expansive and interconnected malware campaigns active throughout...
Researchers at Datadog Security Research have uncovered a major supply-chain compromise in the npm ecosystem involving 17...
The Socket Threat Research Team has uncovered an extensive supply chain attack targeting the npm ecosystem, involving...
Researchers from Palo Alto Networks’ Unit 42 have uncovered a massive, fast-evolving smishing campaign tied to a...
Researchers from Socket’s Threat Research Team have uncovered an active homoglyph typosquat on NuGet impersonating the widely...
The Socket Threat Research Team has sounded the alarm on an escalating wave of malicious npm activity...
Socket’s Threat Research Team has uncovered a supply chain attack involving two malicious Rust crates—faster_log and async_println—that...
Socket’s Threat Research Team has revealed a long-running supply chain attack in the RubyGems ecosystem, where a...
GitLab’s Vulnerability Research team has exposed a sophisticated cryptocurrency theft campaign targeting the Bittensor decentralized AI network...
Socket’s Threat Research Team has uncovered an alarming wave of malicious Go packages—some still live on GitHub—designed...
A deceptive and highly targeted phishing campaign has successfully compromised several popular npm packages, including eslint-config-prettier, eslint-plugin-prettier,...
Cybercriminals are once again exploiting the trust users place in popular platforms like GitHub to spread sophisticated...
Researchers at ReversingLabs (RL) have uncovered a supply chain compromise of the popular ETHcode extension for Visual...
In a detailed expose, the Socket Threat Research Team has uncovered an ongoing and highly targeted supply...
Socket’s Threat Research Team has uncovered a malicious Python package named psslib designed to abruptly shut down...
Researchers at CloudSEK have uncovered a new variant of the Atomic macOS Stealer (AMOS) targeting macOS users...
Socket’s Threat Research Team has uncovered a targeted supply chain attack leveraging malicious RubyGems impersonating Fastlane plugins....