Turn emails into revenue with Brew. No credit card, free credits to try.
socket.dev · newsletter
Explore this email design and adapt it to your own brand. Review the copy, links, and offer before sending.
socket-weekly-new-header
Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.
TOP STORY
OSV Withdraws 157 Malware Reports After Automated False Positives Hit npm and PyPI
OSV withdrew 157 malware reports after automated detections incorrectly flagged trusted npm and PyPI packages, including FastAPI, Strawberry GraphQL, TanStack packages, Nx packages, and other developer tools. Once those reports landed in OSV, they moved through the ecosystem with the same authority as legitimate security intelligence. The false positives activated incident response teams and put the burden on maintainers to prove they were not compromised.
MORE NEWS
Famous Chollima Targets PHP Developers Through Compromised Packagist Package
Famous Chollima, the North Korean threat group known for fake job interview lures, appears to have used a PHP/Packagist package path in a targeted developer lure. Socket found the loader in a compromised Laravel package, on a branch that could be installed through Composer, which is exactly the kind of “clone this repo, check out this branch, install this dependency” workflow developers see in interview tasks and take-home projects.
Rust Moves to Restrict LLM Use in Contributions After Months of Internal Debate
Rust is moving toward an LLM policy for rust-lang/rust after months of debate over how to curb slop PRs. The proposed policy would block LLM-authored code, docs, diagnostics, comments, and PR descriptions. Project leaders and contributors are pushing back over whether the rule is too restrictive, too complicated, and too focused on how a contribution was made instead of whether it is worth reviewing.
MORE WORTH READING
Disrupting Glassworm: Inside CrowdStrike’s Takedown of a Developer-Targeting Botnet
Microsoft under fire for threatening security researcher with criminal investigation
OpenSSF: CRA Due Diligence Needs Machine-Readable OSS Signals
Malicious NuGet Package Impersonates Sicoob SDK to Exfiltrate Banking Certificates and Passwords
OpenAI Publishes Frontier Governance Framework
X
512x512-logo-27148
bluesky
Socket Inc.
Secure your supply chain. Ship with confidence.
2810 N Church St., Suite 71517, Wilmington,DE, 19802
Book a Demo • Unsubscribe