# Socket Weekly: Free VPN Extensions Steal Clipboard Data, Node.js…

Canonical: https://brew.new/browse/templates/email/pt1_k97mdaxtpvrkwec57phgyqwe218e4n9v

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: Free VPN Extensions Steal Clipboard Data, Node.js…](https://cdn.brew.new/email-preview-dfa986281efd5525-tracking_r57xbnbeggd3v6j2fv8cr65h458dt405-1789057643480.png)

## Email content

socket-weekly-new-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates

Socket researchers found Chrome and Firefox extensions posing as free VPNs that added clipboard stealers through later updates. The extensions kept enough proxy functionality to look legitimate while polling users’ clipboards every 500 milliseconds and exfiltrating copied data to attacker-controlled infrastructure. Some also targeted copied Solana addresses, replacing them with attacker-controlled wallet addresses when the extension detected crypto activity.

MORE NEWS

Node.js Considers Public Workflow for Security Reports Amid AI-Driven Surge

Node.js is considering moving lower-severity security reports into public workflows, reserving private embargo handling for higher-severity vulnerabilities. Maintainers say the project is still overwhelmed by duplicated, low-signal reports, and pausing bug bounty rewards “didn’t change anything.”

PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems

The North Korea-linked PolinRider campaign has expanded across npm, PyPI, RubyGems, and GitHub with packages aimed at developers working in AI, crypto, and Web3. The newer findings tie PolinRider to the broader Contagious Interview / Famous Chollima activity, where fake job tasks and open source dependencies are used to pull developer secrets from local environments.

MORE WORTH READING

Measuring OSPO Value

GitHub: Restrict issue creation to collaborators only

Fable 5’s cyber safeguards

JADEPUFFER: Agentic ransomware for automated database extortion

Read-only Actions cache for untrusted triggers

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97mdaxtpvrkwec57phgyqwe218e4n9v)

[Browse email designs](https://brew.new/browse/templates)
