Blogs

Supply Chain Attack on Axios Pulls Malicious Dependency from npm

Socket

A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Visit Site

Blogs Socket

BlogsUpdated and Ongoing Supply Chain Attack Targets CrowdStrike npm PackagesSocket BlogsPopular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain AttackSocket BlogsOpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain AttackSocket BlogsIntroducing Socket Firewall: Free, Proactive Protection for Your Software Supply ChainSocket BlogsAnthropic Identifies Biased Reasoning and Recklessness as Drivers of Claude’s PyPI AttackSocket BlogsIntroducing Dependency Divergence GitHub ActionSocket BlogsHow We Eliminated Long-Lived CI Secrets Across 70+ ReposPulumi ResourcesNO_EXTERNAL_CSS_AT_IMPORTSVercel BlogsHow Mondelez Accelerates Supply Chain Training Across 150+ Global Manufacturing PlantsSynthesia BlogsAnnouncing Socket Certified Patches: One-Click Fixes for Vulnerable DependenciesSocket Newsupm Launches as a Fast, Tiny Package Manager Written in TypeScriptSocket BlogsHappy Birthday, Shai-HuludSocket BlogsGlassWorm Loader Hits Open VSX via Developer Account CompromiseSocket NewsSupply Chain Attacks and Cloud Native: What You Need to KnowThenewstack BlogsAnnouncing dependency caching for Pulumi DeploymentsPulumi BlogsForward Compatibility and Toolchain Management in Go 1.21 - The Go Programming LanguageGo BlogsWebinar Recap: Webinar Recap: Securing the Software Supply Chain with Docker BusinessDocker BlogsHow to Protect Your Projects from the Risks of Deprecated npm PackagesSocket NewsWhen "Everything" Becomes Too Much: The npm Package Chaos of 2024Socket BlogsSecuring the Financial Frontier: How Capital One Uses Socket for Open Source SecuritySocket