Blogs

Turtles, Clams, and Cyber Threat Actors: Shell Usage

Socket

The Socket Threat Research Team uncovers how threat actors weaponize shell techniques across npm, PyPI, and Go ecosystems to maintain persistence and exfiltrate data.

Visit Site

Blogs Socket

BlogsWhen Autonomous Agents Escape: Why Socket Signed the Cyber Defense Open LetterSocket BlogsLarge-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation CampaignSocket BlogsHow to Protect Your Projects from the Risks of Deprecated npm PackagesSocket BlogsSocket for Asana Is Now AvailableSocket BlogsWhy Socket Joined the Open Source Security FoundationSocket BlogsPolinRider Spreads Through Compromised GitHub Accounts and PackagistSocket ResearchA Guide to Extended Threat Detection and Response: What It Is and How to Choose the Best SolutionsCybersecurity Exchange BlogsAI Statistics 2026: Adoption, Usage & Workforce TrendsSynthesia BlogsIntroducing Usage Limits for Pulumi NeoPulumi BlogsReal-world Cyber Attacks Targeting Data Science ToolsAquasec BlogsTrivy supply chain compromise: What Docker Hub users should knowDocker ResourcesNotificationsVercel BlogsSocket Named Among Top Cybersecurity Companies in Fortune’s Cyber 60 ListSocket BlogsUK Cyber Test: AI Agent Attempted to Social Engineer Open Source Maintainer Into Merging MalwareSocket BlogsThreat Alert: Tracking Real-World Apache Log4j AttacksAquasec BlogsRATs in the Cloud: Kubernetes UI Tools Turn into a WeaponAquasec ResourcesReact2Shell Security BulletinVercel BlogsWhat's Really Going On Inside Your node_modules Folder?Socket BlogsWhite House Authorizes Private Companies to Conduct Offensive Cyber OperationsSocket BlogsUnveiling Pulumi ESC Versioning: Manage Secrets and Deployments with ConfidencePulumi