Turn emails into revenue with Brew. No credit card, free credits to try.
socket.dev · newsletter
Explore this email design and adapt it to your own brand. Review the copy, links, and offer before sending.
socket-weekly-header
Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.
TOP STORY
TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack
Attackers published 84 malicious versions across 42 @tanstack/* packages, including @tanstack/react-router (12 million weekly downloads), in the latest wave of the Mini Shai-Hulud campaign. Socket detected the compromised packages within six minutes of publication. The campaign has been working through high-trust namespaces across npm, PyPI, and Packagist for weeks, with earlier waves hitting UiPath, Mistral AI, OpenSearch, and Intercom's PHP and JavaScript SDKs.
MORE NEWS
TeamPCP and BreachForums Launch $1,000 Contest for Supply Chain Attacks
TeamPCP and BreachForums are running a $1,000 Monero contest for the biggest open source supply chain compromise, scored by weekly and monthly download counts, with the usual cybercrime forum currency of reputation and bragging rights on the side. Never ones to miss a punchline, TeamPCP also released Shai-Hulud as open source attack tooling so contestants don't have to write the malware themselves.
Popular node-ipc npm Package Infected with Credential Stealer
Three malicious versions of node-ipc shipped a credential stealer targeting 90+ categories of developer and cloud secrets, exfiltrated through DNS TXT queries to blend into normal traffic. The attacker never touched npm or the active maintainers; they re-registered an expired email domain tied to a dormant maintainer account and used a routine password reset to gain publish rights, a reminder that abandoned accounts on widely used packages are their own category of supply chain risk.
MORE WORTH READING
Mythos finds a curl vulnerability
Packagist Urges Immediate Composer Update After GitHub Actions Token Leak
Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
OpenAI: Our response to the TanStack npm supply chain attack
GitHub App installation tokens: Per-request override header
X
512x512-logo-27148
bluesky
Socket Inc.
Secure your supply chain. Ship with confidence.
2810 N Church St., Suite 71517, Wilmington,DE, 19802
Book a Demo • Unsubscribe