# Socket Weekly: npm Responds as Package Compromises Spread

Canonical: https://brew.new/browse/templates/email/pt1_k97hkv1420xbacj798sq5khcth8e4ya6

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: npm Responds as Package Compromises Spread](https://cdn.brew.new/email-preview-78086b75b6f49658-tracking_r57jt5rsk00r410ckx32afbavd8dtmfd-1789015380915.png)

## Email content

socket-weekly-new-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

npm Ships Staged Publishing and New Install-Time Controls

npm made staged publishing generally available this week, giving maintainers a way to publish package versions that require human approval before they become installable. The feature was already on npm’s roadmap, but it arrived alongside a forced reset of granular access tokens after Mini Shai-Hulud compromised hundreds of packages. npm also added new install-time controls for Git, remote URL, file, and directory dependencies, which have become a recurring blind spot in JavaScript supply chain attacks.

MORE NEWS

Malicious Postinstall Hook Found Across 700+ GitHub Repositories

Socket found the same malicious postinstall hook planted across more than 700 GitHub repositories, including PHP packages on Packagist and Node.js projects. The packages picked up install scripts through compromised upstream repos, putting suspicious JavaScript in a place many Composer users would not commonly check.

Laravel Lang Compromised with RCE Backdoor Across 700+ Versions

Attackers compromised Laravel Lang packages with an RCE backdoor across more than 700 versions, targeting cloud keys, CI/CD secrets, database credentials, and developer environment variables. The packages are used for application localization, turning a routine dependency into a place attackers could hide credential-hunting code across release lines.

MORE WORTH READING

Anthropic’s Mythos Preview Finds 10,000+ Serious Bugs

TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io

GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension

CISA Opens Public Nominations for KEV Catalog

Measuring LLMs’ ability to develop exploits

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97hkv1420xbacj798sq5khcth8e4ya6)

[Browse email designs](https://brew.new/browse/templates)
