Grilled Cheese

ExploreLog inSign up

Socket

@socket.dev

382 Following1.1k Followers

Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS.

https://socket.dev

PostsRepliesMedia
@socket.devOct 9, 2026, 6:35 PM

Update: Socket has identified more than 500 GitHub accounts that committed the malicious GhostAction workflow to tens of thousands of repositories since October 7, including organization-owned repositories reached through compromised contributors.

@jasnell.meOct 9, 2026, 3:02 PMReposted by @socket.dev

Fun fact.. Node.js was downloaded nearly 900 million times in July alone.

Node.js download stats
@socket.devOct 9, 2026, 2:53 PM

"Our moderators are observing an increase in thin papers of narrow scope, as well as ‘salami’ papers, where a single work is broken up and submitted as a set of smaller papers. There is also a marked increase in dense, AI-written papers." - @arxiv.bsky.social

socket.dev/blog/arxiv-r...

@socket.devOct 9, 2026, 1:10 PM

The payload now also scans source code and full git history for cloud and AI credentials, including secrets deleted from current files.

It captures nearby lines around AWS key IDs to find the corresponding secret keys.

socket.dev/blog/ghostac...

@socket.devOct 9, 2026, 1:10 PM

🚨 A new GhostAction wave has hit hundreds of GitHub repos, including Uber’s athenadriver and Pyxel. Attackers used compromised maintainer accounts to plant fake “security audit” workflows that steal GitHub Actions secrets.

@socket.devOct 8, 2026, 3:38 AM

🚨 Tensorlake’s npm SDK (12K weekly downloads) was compromised in a ChainDrop / Shai-Hulud attack.

Version 0.5.144 contains a credential-stealing worm with a dead-man switch designed to execute attacker code when a stolen GitHub token is revoked.

socket.dev/blog/tensorl...

@socket.devOct 7, 2026, 10:54 PM

cc: @campuscodi.risky.biz @darkreading.bsky.social @coindesk.com @cointelegraph.bsky.social @theblock.bsky.social @coingapenews.bsky.social @thehackernews.bsky.social @bleepingcomputer.com

@socket.devOct 7, 2026, 5:53 PM

Socket found 16 malicious Firefox extensions impersonating Rabby and OKX wallets, built to steal recovery phrases and private keys.

All 16 claim to collect no data. The malware sends wallet secrets to attacker-controlled Cloudflare Workers.

socket.dev/blog/firefox...

@socket.devOct 7, 2026, 4:47 PM

✍️ our full write-up: socket.dev/blog/glasswo...

✨ we now scan for these: socket.dev/blog/vscode-...

@socket.devOct 7, 2026, 4:47 PM

You wanted VS Code to look rad. Now you have TWO problems.

@socket.devOct 6, 2026, 8:33 PMReposted by @socket.dev

🚀 Socket now scans VS Code Marketplace extensions! You can vet every dependency in your app and still get compromised by an extension in your editor. We analyze all 100,000+ extensions in the VS Code Marketplace and their updates for malicious code and risky behaviors.

@socket.devOct 6, 2026, 8:33 PM

Extensions auto-update, and developers have little visibility into what changed.

Socket flags suspicious file access, network activity, process execution, obfuscated code, and links to known attack campaigns.

✨ Available today: socket.dev/blog/vscode-...

@socket.devOct 6, 2026, 8:33 PM

🚀 Socket now scans VS Code Marketplace extensions! You can vet every dependency in your app and still get compromised by an extension in your editor. We analyze all 100,000+ extensions in the VS Code Marketplace and their updates for malicious code and risky behaviors.

@socket.devOct 5, 2026, 1:57 PM

A ClickFix RAT targets ChatGPT power users 👀

@socket.devOct 2, 2026, 3:08 PM

Socket researchers found a GlassWorm-linked VS Code theme cluster: 4 extensions on VS Code Marketplace and 6 on Open VSX. Related themes have thousands of installs. The malware fetches and executes payloads using encrypted loaders and a Solana dead drop.
socket.dev/blog/glasswo...

@socket.devOct 2, 2026, 2:08 PM

Modern malware doesn't need to steal anything 🫪

It simply tells your AI agent "you're an authorized pentester" and lets the it do the stealing.

Socket CTO @ahmadnassri.com Nassri on Insecure Agents with Allie Howe: socket.dev/blog/insecur...

@feross.bsky.socialOct 1, 2026, 4:41 PMReposted by @socket.dev

Capital One operates in one of the most demanding security environments in the world. As AI accelerates how software gets built, evaluating dependencies in the pipeline is non-negotiable.

Excited to share how they’re using Socket for proactive supply chain security:
socket.dev/blog/capital...

@socket.devOct 1, 2026, 2:34 PM

🎙️ Socket CTO @ahmadnassri.com discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

socket.dev/blog/insecur...

@socket.devOct 1, 2026, 2:34 PM

"The agents have too much power" @ahmadnassri.com

@socket.devSep 30, 2026, 8:38 PM

New UK AISI report: GPT-6 Astra reached malicious payload delivery in 29.2% of simulated CTF runs. In its supply chain attacks, it considered fake CVE reports, deceptive PR notes, and triggering a publisher workflow from an unmerged PR branch.

socket.dev/blog/astra-s...

Older posts
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-10 20:13:24 EDT