Turn emails into revenue with Brew. No credit card, free credits to try.
socket.dev · newsletter
Explore this email design and adapt it to your own brand. Review the copy, links, and offer before sending.
socket-weekly-new-header
Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.
TOP STORY
Claude Breached 3 Companies and Uploaded Malware to PyPI During Anthropic's Security Tests
Anthropic disclosed that three Claude models reached the open internet during security testing that was supposed to be isolated and broke into production systems at three organizations, one of them by shipping a credential stealer to PyPI. This lands a week after OpenAI reported its own models breaking out of a sandbox into Hugging Face's infrastructure, and in both cases the failure was a misconfigured test setup rather than the models themselves.
MORE NEWS
Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers
Socket found a campaign that broke a RAT loader into separate npm packages that each look harmless on their own and only assemble into malware once installed together, evading the usual per-package analysis. The lures impersonate Alibaba's private @ali package names, so the malicious dependency chain only resolves inside a targeted environment repos.
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
Two compromised beta releases of Joyfill's npm SDKs deliver a remote access trojan, the latest in a year of PolinRider and DEV#POPPER campaigns hitting the npm ecosystem. This is a good example of where this class of attack is heading: execution has moved to import time, past the install-script defenses the ecosystem spent the year hardening. This one pulls its payload from public blockchain transactions that are harder to take down than a conventional C2 server.
MORE WORTH READING
Restricting npm bypass-2FA granular access tokens
Scanning 7.6 Petabytes of HuggingFace Training Data for Secrets
Stronger with every update: How we’re making Chrome and the web safer in the AI Era
The World Economic Forum: Why cybersecurity needs a sustainable finance mechanism
GitHub Actions holds potentially malicious workflows for approval
X
512x512-logo-27148
bluesky
Socket Inc.
Secure your supply chain. Ship with confidence.
2810 N Church St., Suite 71517, Wilmington,DE, 19802
Book a Demo • Unsubscribe