The Rustification of #JavaScript tooling continues: pnpm 12 has been rewritten in Rust, with installs up to 90% faster in testing. Other highlights: project-aware global bins, registry revisions, and deterministic lockfiles for cyclic dependency graphs. https://lnkd.in/eX_zH5As
Socket
Computer and Network Security
Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS.
About us
Socket is a cybersecurity platform that protects companies from software supply chain attacks. Companies use Socket to protect their software applications and critical services from malware and security threats originating in open source code.
- Website
-
https://socket.dev
External link for Socket
- Industry
- Computer and Network Security
- Company size
- 51-200 employees
- Headquarters
- San Francisco
- Type
- Privately Held
- Founded
- 2020
- Specialties
- Software, Security, Software supply chain, Open source software, Application Security, Cybersecurity, and Software Composition Analysis (SCA)
Locations
-
Primary
Get directions
San Francisco, US
Employees at Socket
Updates
-
What happens when AppSec leaders set aside vendor rivalries at Black Hat? 🤔 Socket CTO Ahmad Nassri joined a roundtable of leaders to tackle some of the most pressing issues in open source supply chain security. 🔥 Great panel + a few spicy takes → https://lnkd.in/evTZRU6b
-
Socket reposted this
After all the faked stars and gamed download counts, here's the only thing that actually tells you whether to trust a package: what the code does. Does it reach out to the network? Read your filesystem? Grab your API keys and environment variables? Everything else is a proxy. There's no replacement for reading the code, which is exactly what we built Socket to do at scale. How we think about trust.
-
Socket researchers uncovered more FUNNULL-linked activity on Packagist: 13 malicious themes that expose site visitors to gambling redirects and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware and steals crypto wallet seeds. https://lnkd.in/ez6aNhqN #PHP
-
-
Socket reposted this
OpenAI published an open letter calling for a global surge in cyber defense, alongside a bombshell post-mortem detailing how 1,200 autonomous agents formed a swarm, broke out of constraints, and executed a multi-stage cyberattack on Hugging Face. Socket joined 100+ organizations to sign the letter. Here's why → https://lnkd.in/ekYMUDe4
-
-
🚨 10 malicious OpenAPI React Query Codegen versions were published to npm in a Mini Shai-Hulud attack through a comment-triggered workflow. All carry valid provenance. The latest tag still points to compromised v3.0.4. Anyone who installed an affected version should treat the environment as compromised. https://lnkd.in/eMZ4vdXc
-
OpenAI published an open letter calling for a global surge in cyber defense, alongside a bombshell post-mortem detailing how 1,200 autonomous agents formed a swarm, broke out of constraints, and executed a multi-stage cyberattack on Hugging Face. Socket joined 100+ organizations to sign the letter. Here's why → https://lnkd.in/ekYMUDe4
-
-
Socket reposted this
Socket researchers found 18 Chrome extensions and one Edge extension delivering a wallet drainer and credential-stealing payloads. In several cases, attackers acquired established extensions, then pushed malicious updates to users who already trusted them. https://lnkd.in/ejSjcPsD
-
-
Today we’re bringing Socket’s browser extension security to Edge! 🚀 Security teams can now continuously evaluate extensions from the Microsoft Edge Add-ons store and catch malicious behavior or risky changes as new versions are published. For Edge extensions, teams can now: → Detect malware, credential theft, & data exfiltration → Review permissions and network activity → Compare changes between versions → See if an extension is linked to a broader malicious campaign Available today: https://lnkd.in/e954VxKb
-
-
Socket researchers found 18 Chrome extensions and one Edge extension delivering a wallet drainer and credential-stealing payloads. In several cases, attackers acquired established extensions, then pushed malicious updates to users who already trusted them. https://lnkd.in/ejSjcPsD
-