Blogs

MemTensor npm and PyPI Packages Compromised in Credential-Stealing Supply Chain Attack

Socket

The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents.

Visit Site

Blogs Socket

BlogsUpdated and Ongoing Supply Chain Attack Targets CrowdStrike npm PackagesSocket BlogsPopular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain AttackSocket BlogsOpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain AttackSocket BlogsSupply Chain Attack on Axios Pulls Malicious Dependency from npmSocket BlogsAnthropic Identifies Biased Reasoning and Recklessness as Drivers of Claude’s PyPI AttackSocket BlogsHow to Protect Your Projects from the Risks of Deprecated npm PackagesSocket BlogsPulumi ESC Table Editor Now Supports Dynamic Credential and Secret IntegrationsPulumi BlogsHow We Eliminated Long-Lived CI Secrets Across 70+ ReposPulumi BlogsGodoc: documenting Go code - The Go Programming LanguageGo BlogsGo.dev: a new hub for Go developers - The Go Programming LanguageGo ResourcesManaging dependencies - The Go Programming LanguageGo ResourcesNO_EXTERNAL_CSS_AT_IMPORTSVercel BlogsHow Mondelez Accelerates Supply Chain Training Across 150+ Global Manufacturing PlantsSynthesia BlogsUnderstanding Redis Enterprise Software Support PackagesRedis BlogsAnnouncing Socket Certified Patches: One-Click Fixes for Vulnerable DependenciesSocket BlogsIntroducing Dependency Divergence GitHub ActionSocket Newsupm Launches as a Fast, Tiny Package Manager Written in TypeScriptSocket BlogsHappy Birthday, Shai-HuludSocket BlogsGlassWorm Loader Hits Open VSX via Developer Account CompromiseSocket NewsSupply Chain Attacks and Cloud Native: What You Need to KnowThenewstack