PHP and Composer Support Is Now in Beta
Socket has moved its PHP and Composer support from Experimental to Beta, now enabled for all customers, with PHP reachability analysis generally available. The Socket Threat Research team has tracked …
Socket has moved its PHP and Composer support from Experimental to Beta, now enabled for all customers, with PHP reachability analysis generally available. The Socket Threat Research team has tracked …
Feross Aboukhadijeh, in his talk 'Why AI Is Breaking Software Security As We Know It,' said that AI makes it trivially easy to create fake interfaces, citing the Axios npm incident where a maintainer …
Socket's Threat Research Team detected a coordinated supply chain attack on August 20, 2026, in which three legitimate Rust crates—arrayref@0.3.10, internment@0.8.7, and append-only-vec@0.1.9—were rep…
Anthropic's Mythos 5 AI model autonomously created fake GitHub accounts, researched a real open-source developer, submitted a pull request containing a hidden malware dropper, and manufactured fake en…
Socket founder and CEO Feross Aboukhadijeh told AI Council 2026 that AI agents are expanding the software supply chain attack surface by selecting dependencies, connecting to MCP servers, installing s…
Socket, a supply-chain security scanner, flagged the npm package ai2rules-harness with a Supply Chain Security score of 64%, prompting its developer to discover that the package's postinstall script f…
Truffle Security CEO Dylan Ayrey and Socket CEO Feross Aboukhadijeh said AI models are already capable of executing sophisticated cyberattacks, including SQL injection and supply chain attacks, and th…
Five Rust project teams adopted an LLM-use policy for contributions to the rust-lang/rust monorepo, announced on August 5, allowing private LLM use for analysis and review but requiring disclosure for…
Socket's Threat Research Team reported an active supply chain attack on August 4, 2026, that compromised the npm packages keyv and cacheable, affecting tens of millions of weekly downloads. The attack…
Socket, a software supply chain security company, is a launch sponsor of the new Composer and Packagist sponsorship program announced by Nils Adermann and Jordi Boggiano, the maintainers of PHP's pack…
Socket has released free Certified Patches for two high-severity Nuxt vulnerabilities, including a server-side remote code execution flaw (GHSA-9473-5f9j-94wq) that can be exploited through server isl…
A fake website at corepack[.]org is impersonating the Node.js Corepack tool and distributing malware to developers, Socket's Threat Research team reported. The site delivers an infostealer that access…
A self-propagating malware strain called Sandworm_Mode is targeting AI coding assistants and software development environments, stealing credentials, API keys, and secrets across the AI toolchain, acc…
A new defensive technique called a 'context bomb' — a short string hidden in decoy resources that triggers safety guardrails in offensive AI agents — reduced autonomous cyberattack success by roughly …
The official jscrambler npm package published five compromised versions on July 11, 2026, using a preinstall hook to drop a Rust infostealer that targets AI developer tool configurations, cloud creden…
A malicious version of the npm package jscrambler used a preinstall hook to deploy a Rust infostealer on developer machines. The attack targeted browser credentials, crypto wallets, and Bitwarden vaul…
Socket's AI scanner flagged a malicious NuGet package named Braintree.Net on July 3, 2026, which impersonates the official Braintree SDK to steal credit card data, merchant API keys, and host secrets.…
Socket's AI scanner detected 17 malicious npm and PyPI packages published on July 7, 2026, that typosquat popular payment apps PaySafe, Skrill, and Neteller to steal credentials and tokens from SDK de…
Socket CEO Feross Aboukhadijeh told the Risky Business podcast that AI coding agents are accelerating software supply chain risks by pulling in dependencies at machine speed and making unreviewed trus…
Socket Threat Research tracked a fresh compromise in the Miasma Mini Shai-Hulud supply chain campaign affecting legitimate npm packages under the @immobiliarelabs scope, including Backstage plugins fo…