Turn emails into revenue with Brew. No credit card, free credits to try.
socket.dev · newsletter
Explore this email design and adapt it to your own brand. Review the copy, links, and offer before sending.
socket-weekly-new-header
Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.
TOP STORY
npm Ships Staged Publishing and New Install-Time Controls
npm made staged publishing generally available this week, giving maintainers a way to publish package versions that require human approval before they become installable. The feature was already on npm’s roadmap, but it arrived alongside a forced reset of granular access tokens after Mini Shai-Hulud compromised hundreds of packages. npm also added new install-time controls for Git, remote URL, file, and directory dependencies, which have become a recurring blind spot in JavaScript supply chain attacks.
MORE NEWS
Malicious Postinstall Hook Found Across 700+ GitHub Repositories
Socket found the same malicious postinstall hook planted across more than 700 GitHub repositories, including PHP packages on Packagist and Node.js projects. The packages picked up install scripts through compromised upstream repos, putting suspicious JavaScript in a place many Composer users would not commonly check.
Laravel Lang Compromised with RCE Backdoor Across 700+ Versions
Attackers compromised Laravel Lang packages with an RCE backdoor across more than 700 versions, targeting cloud keys, CI/CD secrets, database credentials, and developer environment variables. The packages are used for application localization, turning a routine dependency into a place attackers could hide credential-hunting code across release lines.
MORE WORTH READING
Anthropic’s Mythos Preview Finds 10,000+ Serious Bugs
TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension
CISA Opens Public Nominations for KEV Catalog
Measuring LLMs’ ability to develop exploits
X
512x512-logo-27148
bluesky
Socket Inc.
Secure your supply chain. Ship with confidence.
2810 N Church St., Suite 71517, Wilmington,DE, 19802
Book a Demo • Unsubscribe
Browse more email designs