Loading...

Tag trends are in beta. Feedback? Thoughts? Email me at [email protected]

New Rust RFC Proposes Adding Support for Trusted Publishing to Crates.io

Automated Spam Campaign Floods GitHub/NPM with 1000s of Garbage Packages

Unverified NPM Account Takeover Vulnerability for Sale on Dark Web Forum

New axobject-query Maintainer Faces Backlash Over Controversial Decision to Support Legacy Node.js Versions

Researchers Uncover npm Registry Vulnerability to Cache Poisoning and DoS Attacks - Socket

Namecheap Takes Down Polyfill.io Service Following Supply Chain Attack

The push to ban ransom payments is gaining momentum

OpenJS: "XZ Utils Cyberattack Likely Not an Isolated Incident"

Node.js TSC Confirms: No Intention to Remove npm from Distribution

CISA Announces Initiative to Fortify Security of Open Source Package Registries - Socket

How to Use Socket to Find out if You Were Affected by the Backdoored xz Package (including full list of npm, PyPI, and Go packages that bundle or link to xz)

New Proposed CISA Mandate Would Require Critical Infrastructure to Report Ransom

Express.js Spam PRs Incident Highlights the Commoditization of Open Source Contributions

Node.js Community Debate Intensifies Over Enabling Corepack by Default and

JSR: What We Know So Far About Deno’s New JavaScript Package Registry

LockBit Takedown: U.S. Sanctions Ransomware Affiliates, International Law

Two Typosquatting Python Packages Exploit Discord CDN to Deploy Malicious

Socket Project Reports v0 Deprecation

The Security Podcast in Silicon Valley: Adopting a Security Mindset in Open

Malicious npm Package Masquerades as Noblox.js, Targeting Roblox Users for Data

LockBit Dubbed “Cyber Crime Unicorn” After Reports Estimate $1B+ in Stolen Funds

Risky Business Podcast: How Socket Combats Malware in Open Source Package

Socket Introduces New Dashboard Threat Feed

CyberBytes Podcast: Open Source Security Shifts Towards Tackling Supply Chain

German Court Fines Security Researcher for Reporting Company's Vulnerabilities

The Everything NPM Package

Biggest package on npm? 5.96 GB! Longest npm package name? 214 characters! Package with the most maintainers? 554 maintainers!

Cyber Insurance Premiums Expected to Increase in 2024, Ransomware Cited as Top

Tines Integration Generates Real-Time Critical Vulnerability Reports from Socket

Orbit Chain Terminates Negotiations, Offers $8M Bounty for Intel Leading to

More →