Socket Headlines

Latest news and coverage for Socket

Filter by headline type:

Recent Headlines

11 headlines

Socket Blog

Introducing Reports: An Extensible Reporting Framework for Socket

Socket launched Reports, a new page in the Socket dashboard providing chart-based views of vulnerabilities, dependencies, and usage across projects. The feature gives security teams better visibility into their software supply chain.

Companies:Socket
AnnouncementApr 22, 2026

Socket Blog

108 Chrome Extensions Linked to Data Exfiltration and Session Theft via Shared C2 Infrastructure

Socket's Threat Research Team identified 108 malicious Chrome extensions operating as a coordinated campaign, stealing credentials, user identities, and browsing data.

Companies:Socket
OSS News & ViewsApr 13, 2026

Help Net Security

Social engineering attacks on open source developers are increasing

Help Net Security reports on the increasing social engineering attacks targeting open source developers, referencing Socket's findings on the Axios compromise.

Companies:Socket
OSS News & ViewsApr 8, 2026

SecurityWeek

North Korean Hackers Target High-Profile Node.js Maintainers

SecurityWeek reports on North Korean threat actors targeting high-profile Node.js maintainers, referencing the Axios supply chain attack.

Companies:Socket
OSS News & ViewsApr 6, 2026

Socket.dev Blog

Trivy Supply Chain Attack Expands to Compromised Docker Images

Socket's threat research team identified additional compromised Trivy artifacts published to Docker Hub, following a previous GitHub Actions compromise. Newly published Docker images (0.69.5 and 0.69.6) were found to contain infostealer indicators of compromise.

Companies:Socket
OSS News & ViewsMar 22, 2026

Socket.dev Blog

Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets

Socket identified a supply chain attack on Trivy GitHub Actions where an attacker force-pushed malicious tags, exposing CI/CD secrets. Socket's research details the attack mechanism and potential impact.

Companies:Socket
OSS News & ViewsMar 20, 2026

Socket.dev Blog

CanisterWorm: npm Publisher Compromise Deploys Backdoor Across 29+ Packages

Socket's Threat Research Team independently identified a worm-enabled npm supply chain attack, dubbed CanisterWorm, affecting legitimate publisher namespaces and deploying backdoors across numerous packages. The article details the attack's progression and mechanism.

Companies:Socket
OSS News & ViewsMar 20, 2026

Dispatch.com

Socket Announces Support for PHP with Composer and Packagist Integration

Socket has announced its new support for PHP, which includes integration with Composer and Packagist. This announcement, made via a press release on Dispatch.com, signifies an expansion of Socket"s capabilities for developers working with PHP.

Companies:Socket
AnnouncementMar 9, 2026

The Hacker News

Fake Laravel Packages on Packagist Deploy RAT via Composer Dependencies

The Hacker News reports on fake Laravel packages found on Packagist that deploy Remote Access Trojans (RATs) through Composer dependencies. This incident highlights a significant supply chain security threat for Laravel developers.

Companies:Socket
OSS News & ViewsMar 4, 2026

Socket Blog

Malicious Packagist Packages Disguised as Laravel Utilities Install an Encrypted PHP RAT via Composer Dependencies

The article discusses the discovery of malicious packages on Packagist that are disguised as Laravel utility tools. These packages install an encrypted PHP Remote Access Trojan (RAT) through Composer dependencies, posing a security risk to developers who unknowingly include them in their projects. The report highlights the importance of vigilance in managing third-party dependencies in PHP development.

Companies:Socket
OSS News & ViewsMar 3, 2026

Forbes

How Socket Plans To Save The World From Open-Source Attacks

Forbes profiled Socket and its founder on the heels of its $40 billion series B round.

Companies:Socket
Media MentionOct 22, 2024

COSS Weekly Newsletter

Stay up to date with the latest news, funding rounds, and announcements from the COSS universe.

Check out COSS Weekly on the web

All information submitted through this form is handled in accordance with the Privacy Policy of Chinstrap Community.

Latest Content from Chinstrap Community

View all