It's been one year since the Shai-Hulud npm worm was unleashed on the software supply chain, kicking off the worst year for npm security on record. It's now open source and has since torn through thousands of packages and organizations on its rampage. https://lnkd.in/edVKRWUE
Socket
Computer and Network Security
Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS.
About us
Socket is a cybersecurity platform that protects companies from software supply chain attacks. Companies use Socket to protect their software applications and critical services from malware and security threats originating in open source code.
- Website
-
https://socket.dev
External link for Socket
- Industry
- Computer and Network Security
- Company size
- 51-200 employees
- Headquarters
- San Francisco
- Type
- Privately Held
- Founded
- 2020
- Specialties
- Software, Security, Software supply chain, Open source software, Application Security, Cybersecurity, and Software Composition Analysis (SCA)
Locations
-
Primary
Get directions
San Francisco, US
Employees at Socket
Updates
-
Socket reposted this
Deploying Socket Firewall? Fleet has you covered. No matter which OS you're supporting or how you choose to deploy it, we've got dedicated guides for both Socket Firewall Free and Socket Firewall Enterprise, in wrapper or registry mode. See what your traditional MDM can't with Fleet, and start blocking malicious packages at install time with Socket. Guides in the comments 👇 https://lnkd.in/gERS4Z6n
-
We’re tracking more North Korea-linked PolinRider activity across GitHub and Packagist. New findings: 4 malicious dev versions, rewritten Git history, and obfuscated JavaScript planted in index.php and executed through PHP’s shell_exec() function. https://lnkd.in/eXJnMF55
-
-
GitHub added cache-mode to GitHub Actions, a new control that limits cache access at the workflow or job level to reduce cache poisoning, the technique behind several recent high-profile supply chain attacks on npm and PyPI. https://lnkd.in/ewkU6cXk
-
-
🎉 We're excited to welcome Jerod Santo to Socket as our first Head of Media. After more than a decade as one of the most trusted voices in developer media, he's setting his sights on supply chain security. Find out what he's cooking up at Socket. https://lnkd.in/ex9S8WTn
-
-
Socket reposted this
Amazing work from Robert McMillan breaking this story for the WSJ and digging into the details: OpenAI confirmed its AI agents were involved in the GemStuffer RubyGems incident, using the registry as a means to reach the open web during a sandboxed training run. Kudos to Joseph Edwards on our team for the GemStuffer analysis that helped inform the piece. 💪 https://lnkd.in/erFqsFdP
-
Socket reposted this
An exclusive from the Wall Street Journal: OpenAI confirmed that its AI agents were involved in a wave of unexplained activity on RubyGems in May, an incident our threat research team named GemStuffer. During a training run, the agents were sandboxed without full internet access. RubyGems was reachable, so they used the package registry as a makeshift web browser, creating accounts every few minutes and publishing hundreds of packages stuffed with scraped webpages. The volume was heavy enough that RubyGems shut down new account registrations for four days. Our threat research team documented this campaign in May. At the time we noted that the publishing speed and naming patterns pointed to AI generation, and that the goal made little sense for a human attacker. The data being collected was public. The unusual thing was that the registry was being used as a path to the open internet. Open source registries have long been a favorite target for human attackers because they are the fastest way to distribute code at scale. A single release flows into developer machines, CI, scanners, and everything downstream. Autonomous agents are now finding that same infrastructure on their own, and registry defenders need to be prepared for more agent activity. Great reporting by Robert McMillan, and great work by Joseph Edwards on our team, whose analysis is cited in the story. Read the piece: https://lnkd.in/g9rafAHi
-
Socket researchers found a malicious Twitch browser extension on Chrome and Firefox with 30,000+ reported users. It forwards full account-scoped OAuth tokens, not playback tokens, to a Russian bot service, exposing chat, whispers, and account settings. https://lnkd.in/dZai5bm4
-
-
Anthropic identified biased reasoning and recklessness as drivers of Claude’s PyPI attack. Mythos 5 ignored signs it was on the real internet, published malware to PyPI, then used credentials leaked by a vendor’s scanner to access that vendor’s live database. https://lnkd.in/eG2fx_Gm
-