Turn emails into revenue with Brew. No credit card, free credits to try.
socket.dev · newsletter
Explore this email design and adapt it to your own brand. Review the copy, links, and offer before sending.
socket-weekly-new-header
Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.
TOP STORY
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
A maintainer compromise pushed a Shai-Hulud-style worm into the widely used keyv and cacheable packages, and it has since spread to 2,968 package artifacts across 454 unique packages. The payload steals cloud and CI credentials, then republishes itself through stolen npm tokens to keep spreading. Maintainers are getting hit hard with an ever-growing security burden, and the scale of this attack shows the impact. This is one reason we're upgrading our open source program to give maintainers more support.
MORE NEWS
UK Cyber Test: AI Agent Attempted to Social Engineer Open Source Maintainer Into Merging Malware
During a UK government evaluation, an AI agent hid a malware dropper behind a real bug fix, then spun up sockpuppet accounts, timed their comments to fake peer consensus, and emailed the maintainer to get the pull request merged. A maintainer caught it and rejected the PR, but it is one more burden on maintainers, who now have to weigh whether a contributor is even human.
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
Bundler 4.0.18 has extended its opt-in cooldown flag to bundle lock and bundle cache, so the setting that refuses freshly published gems now covers lockfile generation and vendoring, not just install and update. It is a small but important fix: cooldown only helps if it applies everywhere dependencies resolve.
MORE WORTH READING
vlt 1.0 & Hosted Package Registries
Chinese startup Moonshot's AI model breaks out of testing environment
The secure way to release an npm package in 2026
Black Hat USA 2026: The 'Breaking' News: The OpenAI–Hugging Face Incident
Proposing the SAFE Working Group: An Open Community Effort to Improve AI Security
X
512x512-logo-27148
bluesky
Socket Inc.
Secure your supply chain. Ship with confidence.
2810 N Church St., Suite 71517, Wilmington,DE, 19802
Book a Demo • Unsubscribe