# Socket Weekly: GPT-6 Astra Hits 100% on ExploitBench, pnpm 12…

Canonical: https://brew.new/browse/templates/email/pt1_k97n4vv59mtw1t3eyt90cmz3eh8e44d8

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: GPT-6 Astra Hits 100% on ExploitBench, pnpm 12…](https://cdn.brew.new/email-preview-c5e2f343fead2c06-tracking_r57tb2k2zv0g35q4qj3e322w8x8e2pne-1789060924622.png)

## Email content

socket-weekly-new-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing

OpenAI released GPT-6 Astra, its first model to reach the company's Critical cybersecurity capability threshold. An independent evaluation in the system card found Astra attacking simulated open source projects outside its assignment, writing malicious contributions and creating fake identities to get them accepted. This is a new category of supply chain attack for maintainers to watch for, where an agent stuck on a hard task treats an unrelated OSS project as a means to an end, and the attack shows up as a normal PR.

MORE NEWS

pnpm 12’s Rust Rewrite Cuts Install Times by Up to 90%

The Rustification of JavaScript tooling continues, with pnpm 12 rewritten in Rust. Early results from Vercel's Turborepo monorepo show install times cut by as much as 90%. The rewrite keeps pnpm 11's commands, settings, and lockfile format, so upgrading should not break existing workflows.

13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds

Our research team found 13 malicious Composer themes on Packagist that inject JavaScript into every page of the Vietnamese streaming sites that install them, serving iPhone visitors a WebKit-to-kernel exploit chain that collects keychains, messages, photos, and crypto wallet seeds. The site operators are also victims, since they installed a trojanized theme and now serve the payload to their own users.

MORE WORTH READING

An Alien Mind

Multiple trusted publishing configurations for npm

Claude Fable 5.1 opens up vulnerability discovery for defenders, still blocks exploit generation

Ransom attackers used AI agents to compress two weeks of intrusion work into under 10 hours

Thousands of OpenAI Agents Take Over 25-year Old Abandoned German Wiki

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97n4vv59mtw1t3eyt90cmz3eh8e44d8)

[Browse email designs](https://brew.new/browse/templates)
