Blogs

Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan

Socket

Two Joyfill npm beta releases contain an import-time implant that uses blockchain transactions to retrieve a remote-access trojan.

Visit Site

Blogs Socket

BlogsPopular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain AttackSocket BlogsOpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain AttackSocket BlogsUpdated and Ongoing Supply Chain Attack Targets CrowdStrike npm PackagesSocket BlogsHow to Protect Your Projects from the Risks of Deprecated npm PackagesSocket BlogsPolinRider Spreads Through Compromised GitHub Accounts and PackagistSocket BlogsSupply Chain Attack on Axios Pulls Malicious Dependency from npmSocket BlogsHow to connect Google Sheets to NotionZapier NewsWhen CI Meets CD: Deliver With ConfidenceThenewstack NewsLessons Swift Designer Chris Lattner Has Learned about LeadershipThenewstack BlogsIaC Best Practices: Implementing RBAC and SecurityPulumi BlogsPkg.go.dev has a new look! - The Go Programming LanguageGo BlogsGo.dev: a new hub for Go developers - The Go Programming LanguageGo BlogsModal SDKs for JavaScript and Go (alpha)Modal BlogsSvelte for the Experienced React DevCss Tricks BlogsMultiple Class / ID and Class SelectorsCss Tricks BlogsBuilding a Remote MCP Server: OAuth, Tool Design & Lessons from 4,000+ AI Queries | MotherDuckMotherduck BlogsReal-Time Computational Physics with Wafer-Scale Processing [updated]Cerebras NewsCerebras Announces Six New AI Datacenters Across North America and Europe to Deliver Industry’sCerebras BlogsDocker Desktop 4.18: Docker Scout Updates, Container File Explorer GADocker ResourcesConfig and Secret environment variablesVercel