Socket Is Sponsoring Composer and Packagist
Socket, a software supply chain security company, is a launch sponsor of the new Composer and Packagist sponsorship program announced by Nils Adermann and Jordi Boggiano, the maintainers of PHP's pack…
Socket, a software supply chain security company, is a launch sponsor of the new Composer and Packagist sponsorship program announced by Nils Adermann and Jordi Boggiano, the maintainers of PHP's pack…
A self-propagating malware strain called Sandworm_Mode is targeting AI coding assistants and software development environments, stealing credentials, API keys, and secrets across the AI toolchain, acc…
A new supply chain attack wave from the Mini Shai-Hulud, Miasma, and Hades malware family has compromised LeoPlatform and RStreams npm packages, GitHub Actions workflows, and the Verana Blockchain Go …
Docker Security Dispatch Issue 3 reports on major supply chain incidents including the TanStack and Nx Console compromise, the persistence of the Mini Shai-Hulud npm worm, and a kernel-level container…
OpenAI will revoke code-signing certificates for ChatGPT Desktop, Codex App, Codex CLI, and Atlas on June 26, 2026, after a supply chain attack via the Mini Shai-Hulud worm compromised employee device…
Socket Threat Research identified shai_hulululud@1.0.48596, an npm package designed to probe AI-based malware scanners using prompt injection, token flooding, and obfuscated JavaScript. The package co…