# Socket Weekly: OSV False Positives, Famous Chollima, Rust to Restrict…

Canonical: https://brew.new/browse/templates/email/pt1_k97rmme195a3y0mq6xxsya65t98e4f30

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: OSV False Positives, Famous Chollima, Rust to Restrict…](https://cdn.brew.new/email-preview-7bef5b46c627650b-tracking_r57phh6bepdg3zb32j56ybry9d8dtjj5-1789015384029.png)

## Email content

socket-weekly-new-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

OSV Withdraws 157 Malware Reports After Automated False Positives Hit npm and PyPI

OSV withdrew 157 malware reports after automated detections incorrectly flagged trusted npm and PyPI packages, including FastAPI, Strawberry GraphQL, TanStack packages, Nx packages, and other developer tools. Once those reports landed in OSV, they moved through the ecosystem with the same authority as legitimate security intelligence. The false positives activated incident response teams and put the burden on maintainers to prove they were not compromised.

MORE NEWS

Famous Chollima Targets PHP Developers Through Compromised Packagist Package

Famous Chollima, the North Korean threat group known for fake job interview lures, appears to have used a PHP/Packagist package path in a targeted developer lure. Socket found the loader in a compromised Laravel package, on a branch that could be installed through Composer, which is exactly the kind of “clone this repo, check out this branch, install this dependency” workflow developers see in interview tasks and take-home projects.

Rust Moves to Restrict LLM Use in Contributions After Months of Internal Debate

Rust is moving toward an LLM policy for rust-lang/rust after months of debate over how to curb slop PRs. The proposed policy would block LLM-authored code, docs, diagnostics, comments, and PR descriptions. Project leaders and contributors are pushing back over whether the rule is too restrictive, too complicated, and too focused on how a contribution was made instead of whether it is worth reviewing.

MORE WORTH READING

Disrupting Glassworm: Inside CrowdStrike’s Takedown of a Developer-Targeting Botnet

Microsoft under fire for threatening security researcher with criminal investigation

OpenSSF: CRA Due Diligence Needs Machine-Readable OSS Signals

Malicious NuGet Package Impersonates Sicoob SDK to Exfiltrate Banking Certificates and Passwords

OpenAI Publishes Frontier Governance Framework

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97rmme195a3y0mq6xxsya65t98e4f30)

[Browse email designs](https://brew.new/browse/templates)
