DevTools Podcast: Rethinking Open Source Security Beyond Buzzwords

Orbit Bridge Hackers Drain $81 Million in Crypto Assets

Silent Discord Raider: 'Blank Grabber’ Python Package Steals Info from Discord

How Hackers are Using Package Managers as Vectors for Deploying Coinminer

Socket for GitHub v2 Introduces Diff Reports, Speeds Up Scan Times

How to Protect Your Projects from the Risks of Deprecated npm Packages

A Short History of Protestware

Syntax Podcast: "Is Running Random Code From npm Safe?"

Judicious JSON

ALPHV/Blackcat Ransomware Group Fires Back with Escalated Hostility, Following

Strengthening Crypto Supply Chain Security Is a Necessity, Not an Option

How to Integrate Socket Into Your Bitbucket Pipeline

2023 Ransomware Trends: Rising Ransom Payments Drive Higher Demand for Cyber

Stay Ahead of npm Malware: Introducing Socket's Real-Time Threat Feed on X

Socket CLI v0.9.0 Now Available

Social engineering campaign targeting tech employees spreading through npm malware

Introducing the New Socket Project Health Reports: Smarter, Faster, and More

Risky Biz Podcast: Using LLMs for Analysis and Explanation in Software Supply

Introducing Dependency Divergence GitHub Action

Socket (package security tool) Introduces Go Support

Announcing Self-Service Payment Plans

Introducing Go Support - Socket

The “Skeleton Squad” is now targeting NPM

Unveiling the Dangers of the "AnyDesk-Malcom" Malicious Python Package

Announcing $20M Series A to Secure Open Source Software

Socket Security Scan - August 10

Why Socket is the Best Tool for Developers to Stop Supply Chain Attacks

Cleaning up import paths in JS/TS packages

Announcing the Socket Web Extension

Social engineering campaign targeting tech employees spreads through NPM malware

More →