Turn emails into revenue with Brew. No credit card, free credits to try.
socket.dev · newsletter
Explore this email design and adapt it to your own brand. Review the copy, links, and offer before sending.
socket-weekly-header
Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.
TOP STORY
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Following the axios compromise, one of the worst supply chain attacks to hit npm, the maintainer confirmed it was social engineering. That disclosure opened the floodgates: maintainers behind Lodash, Fastify, dotenv, mocha, Express, Node.js core, and many more, have all confirmed they were targeted in the same coordinated campaign, linked to DPRK-nexus group UNC1069.
The playbook: fake companies, real Slack workspaces, spoofed video calls, and a prompt to install a "missing component" that drops a RAT. A compromised maintainer account is a direct write path into packages downloaded billions of times a week, and several of these attempts came frighteningly close.
MORE NEWS
The Hidden Blast Radius of the Axios Compromise
Axios only needed to be resolved somewhere in your dependency graph to affect you. This technical deep dive shows how open version ranges, transitive dependencies, and runtime installs can exponentially expand the blast radius of this compromise.
$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation
North Korean operators spent six months building relationships with Drift contributors, including in-person meetings and shared tooling, before stealing $285M. This is another example of patient, high-touch social engineering designed to blend into legitimate developer and business interactions.
MORE WORTH READING
Securing the open source supply chain across GitHub
RubyGems Fracture Incident Report
Node.js Drops Bug Bounty Rewards After Funding Dries Up
CERT-EU Confirms European Commission Cloud Breach via Trivy Supply Chain Compromise
Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208)
X
512x512-logo-27148
bluesky
Socket Inc.
Secure your supply chain. Ship with confidence.
2810 N Church St., Suite 71517, Wilmington,DE, 19802
Book a Demo • Unsubscribe