Socket Headlines
Latest news and coverage for Socket
Recent Headlines
11 headlinesSocket Blog
Introducing Reports: An Extensible Reporting Framework for Socket
Socket launched Reports, a new page in the Socket dashboard providing chart-based views of vulnerabilities, dependencies, and usage across projects. The feature gives security teams better visibility into their software supply chain.
Socket Blog
108 Chrome Extensions Linked to Data Exfiltration and Session Theft via Shared C2 Infrastructure
Socket's Threat Research Team identified 108 malicious Chrome extensions operating as a coordinated campaign, stealing credentials, user identities, and browsing data.
Help Net Security
Social engineering attacks on open source developers are increasing
Help Net Security reports on the increasing social engineering attacks targeting open source developers, referencing Socket's findings on the Axios compromise.
SecurityWeek
North Korean Hackers Target High-Profile Node.js Maintainers
SecurityWeek reports on North Korean threat actors targeting high-profile Node.js maintainers, referencing the Axios supply chain attack.
Socket.dev Blog
Trivy Supply Chain Attack Expands to Compromised Docker Images
Socket's threat research team identified additional compromised Trivy artifacts published to Docker Hub, following a previous GitHub Actions compromise. Newly published Docker images (0.69.5 and 0.69.6) were found to contain infostealer indicators of compromise.
Socket.dev Blog
Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets
Socket identified a supply chain attack on Trivy GitHub Actions where an attacker force-pushed malicious tags, exposing CI/CD secrets. Socket's research details the attack mechanism and potential impact.
Socket.dev Blog
CanisterWorm: npm Publisher Compromise Deploys Backdoor Across 29+ Packages
Socket's Threat Research Team independently identified a worm-enabled npm supply chain attack, dubbed CanisterWorm, affecting legitimate publisher namespaces and deploying backdoors across numerous packages. The article details the attack's progression and mechanism.
Dispatch.com
Socket Announces Support for PHP with Composer and Packagist Integration
Socket has announced its new support for PHP, which includes integration with Composer and Packagist. This announcement, made via a press release on Dispatch.com, signifies an expansion of Socket"s capabilities for developers working with PHP.
The Hacker News
Fake Laravel Packages on Packagist Deploy RAT via Composer Dependencies
The Hacker News reports on fake Laravel packages found on Packagist that deploy Remote Access Trojans (RATs) through Composer dependencies. This incident highlights a significant supply chain security threat for Laravel developers.
Socket Blog
Malicious Packagist Packages Disguised as Laravel Utilities Install an Encrypted PHP RAT via Composer Dependencies
The article discusses the discovery of malicious packages on Packagist that are disguised as Laravel utility tools. These packages install an encrypted PHP Remote Access Trojan (RAT) through Composer dependencies, posing a security risk to developers who unknowingly include them in their projects. The report highlights the importance of vigilance in managing third-party dependencies in PHP development.
Forbes
How Socket Plans To Save The World From Open-Source Attacks
Forbes profiled Socket and its founder on the heels of its $40 billion series B round.
COSS Weekly Newsletter
Stay up to date with the latest news, funding rounds, and announcements from the COSS universe.
Check out COSS Weekly on the webLatest Content from Chinstrap Community
View allCOSS Weekly – Week of April 27, 2026
This week in COSS: Orkes raised $60M to build more reliable AI workloads, while Tencent and Alibaba ...
COSS Weekly – Week of April 20, 2026
This week in COSS: Mistral raised $830 million in debt financing for AI data center expansion, OpenA...
COSS Weekly – Week of April 13, 2026
This week in COSS: Mastra raised a $22M Series A to help developers build agents, GitButler secured ...
Documentation is Your Friend
Programmers hate documentation. The reason probably lies deep in the psychology of coders, but it’s ...
What Universities Need to Know About Commercial Open Source
By Heather Meeker Open source software has been around long enough that most people understand the b...
Open Source File Server Market Overview
A press release today stated that the open source file server market is “positioned for significant ...
Entire’s Bet on COSS Makes Sense
TechCrunch recently reported that Thomas Dohmke, former GitHub CEO, just raised $60 million at a $30...
MinIO Mothballs its Open Source Version
MinIO, formerly a COSS dual-licensor under AGPL, recently announced that its open source repository ...

