Turn emails into revenue with Brew. No credit card, free credits to try.
socket.dev · newsletter
Explore this email design and adapt it to your own brand. Review the copy, links, and offer before sending.
socket-weekly-new-header
Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.
TOP STORY
jscrambler npm Package Compromised to Drop Infostealers on Linux, macOS, and Windows
An attacker used a stolen npm publishing credential to push five malicious jscrambler releases (8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0), each dropping a Rust infostealer that targets crypto wallets, cloud credentials, and AI assistant and MCP configs. Socket flagged the first version six minutes after publication, and later releases moved the payload off the install hook so it runs on import and survives npm install --ignore-scripts.
MORE NEWS
npm v12 Ships With Install Scripts Off by Default, Begins Deprecating 2FA-Bypass Tokens
npm v12 is out, turning off install scripts by default and beginning the wind-down of 2FA-bypass publishing tokens, a real dent in the entry point behind almost every worm and credential stealer since late 2025. It doesn't touch code that only runs when a package is imported and used, as seen in the jscrambler compromise where attackers already shifted to import-time execution to route around it.
Compromised Injective SDK Steals Wallet Keys and Mnemonics Through Fake Telemetry
Attackers used a legitimate contributor's GitHub account to slip a backdoor into @injectivelabs/sdk-ts, hooking its key-derivation functions to log mnemonics and private keys and exfiltrate them through traffic that blends in with Injective's own public infrastructure. The payload runs when the library is used rather than at install time, and the actor pushed the same version across 17 more @injectivelabs packages to catch transitive users.
MORE WORTH READING
What's new in ECMAScript 2026
CISA details security lapses that led to GitHub leak of passwords, cloud access keys
Rewriting Bun in Rust
Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories
Zero Trust for AI agents
X
512x512-logo-27148
bluesky
Socket Inc.
Secure your supply chain. Ship with confidence.
2810 N Church St., Suite 71517, Wilmington,DE, 19802
Book a Demo • Unsubscribe