Socket Headlines
Latest news and coverage for Socket
Recent Headlines
41 headlinesCybernoz
145 Mastra npm Packages Compromised via Hijacked Contributor Account - Cybernoz
Socket is among the security firms that reported on the compromise of 145 Mastra npm packages via a hijacked contributor account.
Cybernoz
Hackers Target npm Ecosystem by Compromising 140+ Mastra Packages - Cybernoz
Socket Research Team uncovered a large-scale supply chain attack on Mastra npm packages using typosquatting dependency easy-day-js.
InfoSec Today
144 Mastra npm Packages Compromised via Hijacked Contributor Account - InfoSec Today
Socket contributed to the discovery of a supply chain attack compromising 144 Mastra npm packages via the easy-day-js typosquatting dependency.
Data Today
Miasma worm: live coverage of the Red Hat npm attack | Data Today
Data Today's live coverage of the Miasma worm includes multiple references to Socket's research, campaign tracker, and detection of the PyPI wave.
developer-tech.com
Replit deploys Socket Firewall to secure AI development fullstack
Replit integrates Socket Firewall into its IDE to block malicious packages in real time during AI-assisted development.
Digg
Replit Launches Package Firewall With Socket To Block Malware
Replit partnered with Socket to launch a Package Firewall that blocks malicious packages before they reach apps.
Phoenix Security
Miasma Supply Chain Attack: Azure Hit, 73 Repos Down, 37 PyPI Wheels
Phoenix Security analyzes the Miasma campaign, referencing Socket's discovery of 37 malicious PyPI wheels and the broader campaign tracking.
SecurityWeek
Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks - SecurityWeek
SecurityWeek reports on the Miasma/Hades supply-chain campaign, citing Socket's research and campaign tracker documenting over 100 affected packages.
HackWire
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages | HackWire
Article republishing BleepingComputer's report on Socket's discovery of Shai-Hulud attack on PyPI packages.
BleepingComputer
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
BleepingComputer reports on a Shai-Hulud supply-chain attack discovered by Socket, which identified 37 malicious PyPI packages using .pth startup hooks.
Safeguard.sh Blog
TrapDoor Crypto Stealer Supply Chain Attack - May 2026
Safeguard.sh analyzes the TrapDoor attack, referencing Socket's disclosure and detection methods.
SecurityBrief
Socket raises USD $60 million to tackle code risks
Socket raises $60M Series C at $1B valuation led by Thrive Capital to secure software supply chains.
ForkLog
Socket Uncovers Supply Chain Attack on Cryptocurrency and AI Developers
Socket reports a supply chain attack targeting crypto and AI developers.
Menlo Times
How Socket is Securing AI-Driven Software Development
Socket raises $60M and expands security platform to protect AI-driven development from supply chain attacks.
Crypto Economy
Socket Security Flags 34 Malicious Packages Striking Major Crypto Ecosystems - Crypto Economy
Crypto Economy reports on Socket's detection of 34 malicious packages in a campaign targeting crypto ecosystems.
Glitchwire
Socket Flags 'TrapDoor' Campaign Stealing Crypto Wallets and Cloud Credentials Across npm, PyPI, and Crates.io — Glitchwire
Glitchwire covers Socket's disclosure of the TrapDoor campaign, which steals credentials across multiple package registries.
Ventureburn
Socket Raises $60M to Strengthen AI Security - Ventureburn
Ventureburn reports on Socket's $60M Series C funding to enhance AI security and supply chain protection.
SiliconANGLE
Code security startup Socket raises $60M in funding - SiliconANGLE
SiliconANGLE reports Socket's $60M Series C funding at $1B valuation, with details on platform and plans.
Pulse 2.0
Socket: $60 Million Series C Raised At $1 Billion Valuation To Help Enterprises Secure AI-Generated Code
Pulse 2.0 reports Socket's $60M Series C funding, emphasizing protection for AI-generated code.
Socket Blog
Socket raises $60M Series C at $1B valuation led by Thrive Capital to secure AI-driven software development
Socket announces $60M Series C funding at $1B valuation led by Thrive Capital to expand software supply chain security for AI-driven development.
BleepingComputer
Popular node-ipc npm package compromised to steal credentials
Socket detected the node-ipc compromise and provided analysis.
BleepingComputer
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
Socket tracked 416 compromised package artifacts in the Shai Hulud attack.
heise online
Supply chain attack on TanStack: 42 packages compromised | heise online
heise online reports on the TanStack attack, quoting Socket's recommendations for developers.
The Register
Cache-poisoning caper turns TanStack npm packages toxic
The Register covers the TanStack npm package compromise, mentioning Socket's tracking of the campaign.
CyberScoop
‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack | CyberScoop
Article about Mini Shai-Hulud malware includes commentary from Snyk's Stephen Thoemmes, highlighting Snyk's role in security research.
COSS Weekly Newsletter
Stay up to date with the latest news, funding rounds, and announcements from the COSS universe.
Check out COSS Weekly on the webLatest Content from Chinstrap Community
View allCOSS Weekly – Week of July 27, 2026
This week in COSS: On the funding front, Databricks raised $3 billion at a $188 billion valuation, e...
COSS Weekly – Week of July 20, 2026
This week in COSS: Nous Research, the startup behind the OSS Hermes agent, is in talks to raise mew ...
Battle of the Software Acronyms: BYOC Is Beating SaaS, but the Winner is COSS
On June 15, 2026, Ververica, a company founded by the original creators of the open source Apache Fl...
COSS Weekly – Week of July 13, 2026
This week in COSS: Ollama raises a $65M Series B, Bespoke Labs announces a $40M Seed and Series A, a...
COSS Weekly – Week of July 6, 2026
This week in COSS: Together AI announced an $800M Series C to accelerate the shift to open-source AI...
COSS Weekly – Week of June 29, 2026
This week in COSS: The acquisition trend continued as Qualcomm agreed to acquire Modular for nearly ...
COSS Weekly – Week of June 22, 2026
This week in COSS: Databricks reported annualized revenue of $6.9 billion — up over 80% year-over-ye...
COSS Weekly – Week of June 15, 2026
This week in COSS: The recent flurry of COSS M&A activity continues as VoidZero was acquired by Clou...

