Turn emails into revenue with Brew. No credit card, free credits to try.
socket.dev · newsletter
Explore this email design and adapt it to your own brand. Review the copy, links, and offer before sending.
socket-weekly-new-header
Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.
TOP STORY
140+ Mastra npm Packages Compromised in Coordinated Supply Chain Attack
More than 140 @mastra/* npm packages were compromised in a coordinated supply chain attack. In a pattern eerily reminiscent of the Axios compromise, the Mastra packages stayed clean while the newly added easy-day-js dependency, a dayjs typosquat that first appeared as a decoy package, was later updated with a malicious postinstall hook. The payload was a cross-platform infostealer built to pull browser data, crypto wallet extension data, and other developer secrets during install.
MORE NEWS
GitHub Actions Checkout Now Blocks Risky pull_request_target Checkouts
GitHub is changing actions/checkout to block a pull_request_target pattern that researchers have warned about for years: privileged workflows checking out and running code from untrusted pull requests. The fix comes after a punishing run of supply chain attacks exploited privileged PR workflows, including Nx, PostHog’s Shai-Hulud incident, and TanStack, where routine PR automation became a path to tokens, secrets, cache poisoning, and unauthorized package publishing.
npm Package Uses Prompt Injection and Token Flooding to Disrupt AI Malware Scanners
A newly published npm package hid obfuscated JavaScript at the end of a 9 MB index.js packed with safety-triggering comments, fake system override instructions, and context flooding. The setup could trigger refusals, exhaust context windows, bury the executable path, or push a scanner to fail open. This attempt was conspicuous and noisy, but it shows where things are headed: attackers are starting to treat AI scanners as an attack surface.
MORE WORTH READING
The CRA Readiness Reality: What Changed (The CRA Readiness Reality: What Changed (and What Didn’t) Between 2025 and 2026?
GlassWASM: WebAssembly Malware Found in Trojanized Open VSX Extensions
Announcing TypeScript 7.0 RC
Why pnpm no longer expands environment variables in a repository's .npmrc
X
512x512-logo-27148
bluesky
Socket Inc.
Secure your supply chain. Ship with confidence.
2810 N Church St., Suite 71517, Wilmington,DE, 19802
Book a Demo • Unsubscribe