#0001
Socket15 days ago12 min▣LLM reportcritical An active supply chain attack compromised the maintainer account for the keyv and cacheable npm package families, injecting malicious preinstall hooks into at least 14 packages with tens of millions of weekly downloads. The two-stage payload downloads a standalone Bun runtime to execute a heavily obfuscated second stage that harvests cloud, CI, and npm credentials, self-propagates by republishing trojanized packages via stolen tokens, and exfiltrates encrypted data through GitHub repositories and DNS-resolved destinations. Persistence is maintained through .claude and .vscode autostart hooks that re-trigger the malware when repositories are cloned.
#0002
Socket21 days ago11 min▣LLM reporthigh Attackers distributed malicious functionality across a cluster of npm packages that impersonate private Alibaba (@ali scope) packages, triggering a multi-stage download chain that ultimately deploys a cross-platform RAT named aone-cli. The malware employs a Node.js vm sandbox-escape technique to gain process-level access, uses Alibaba Cloud OSS and a compromised GitHub repository to blend malicious traffic with legitimate infrastructure, and establishes persistence via shell profile modification, Launch Agents, code injection into AI tooling, and replacement of a legitimate security application's core code on Windows.
#0003
Socket22 days ago12 min▣LLM reportcritical Two beta releases of the @joyfill npm packages were compromised at build time with a multi-layered obfuscated implant that triggers on module import rather than via npm lifecycle hooks. The implant resolves payloads through Tron/Aptos/BNB Smart Chain transactions to fetch a 77KB Node.js RAT (Socket.IO C2, ss_* command set) and, via a detached process, a separate bootstrap that can deploy a Python infostealer targeting credentials, browser data, and wallet extensions. Code and operational indicators tie the loader to the PolinRider family and the final payload to the DEV#POPPER campaign, with the compromise attributed to maintainer-side access rather than a fake-repo lure.
#0004
Socket26 days ago10 min▣LLM reporthigh Threat actors registered corepack.org to impersonate the legitimate Corepack npm tool following its removal from bundled Node.js releases, capitalizing on developer search traffic to distribute malware disguised as a VPN client installer. The payload combines infostealer capabilities (browser data, SSH key access, host/process discovery, PowerShell execution, run-key persistence) with OpenShield proxyware that silently enrolls the host as a bandwidth-sharing proxy node, while a separate redirect chain on the same site delivers adware/trojan-flagged installers through affiliate marketing infrastructure.
#0005
Socket27 days ago11 min▣LLM reportcritical A large-scale campaign abuses compromised GitHub repositories to weaponize GitHub Actions runners as distributed scanning and exploitation infrastructure targeting internet-facing cPanel and WHM systems via CVE-2026-41940. Malicious workflow files download a Linux payload from a C2 server at 43.228.157.68, scan for vulnerable hosts, exploit the authentication bypass, and exfiltrate harvested credentials through chunked HTTP POST requests. The campaign extends far beyond the initially identified compromised Packagist maintainer, with approximately 6,100 to 16,000 matching workflow files identified across unrelated GitHub repositories.
#0006
Socketabout 1 month ago16 min▣LLM reporthigh Eleven malicious NuGet DotnetTool packages masquerading as game cheats deliver a two-stage Windows payload. The first-stage .NET downloader resolves GitHub hosts via DNS-over-HTTPS to bypass local DNS controls, requests UAC elevation to resync the system clock, and fetches pepesoft.exe from GitHub Releases and Hugging Face. The second-stage PyInstaller-packed Python payload exfiltrates hardware fingerprints, system information, IP geolocation, and screenshots to Google Sheets and Telegram, with a server-side ban-list and hardware binding for licensing enforcement across all recovered builds.
#0007
Socketabout 1 month ago13 min▣LLM reporthigh Socket's Threat Research Team identified four compromised npm packages in the @asyncapi namespace delivering a multi-stage botnet loader called Miasma. The attack injects obfuscated JavaScript into package source files that executes at module load time (bypassing npm lifecycle script blocking), spawns a detached Node.js process to download an encrypted payload from IPFS, and deploys a 3+ MB tasking framework with multi-channel C2 capabilities including HTTP, Nostr, IPFS, and Ethereum RPC. The malicious packages were published via GitHub Actions trusted publishing from a compromised source commit on the 'next' branch.
#0008
Socketabout 1 month ago11 min▣LLM reporthigh A compromised release of the jscrambler npm package (versions 8.14.0 through 8.20.0) delivered a Rust-built cross-platform infostealer via hidden native binaries embedded in an obfuscated CSI container. The malware executes automatically during npm install via a preinstall hook or, in later versions, through injected self-executing functions in package entry points, evading --ignore-scripts protections. The infostealer broadly harvests developer credentials including cryptocurrency wallets, AI assistant API keys, cloud provider credentials, browser data, and messaging app tokens, exfiltrating them over TLS via rustls.
#0009
Socketabout 1 month ago11 min▣LLM reportcritical A malicious NuGet package named Braintree.Net typosquats the legitimate PayPal Braintree .NET SDK and implements a multi-stage .NET implant that intercepts payment card data, exfiltrates merchant API credentials, and harvests environment secrets upon assembly load. The package uses .NET ModuleInitializer attributes for code execution, production-only gating to avoid detection during QA, and XOR obfuscation for one of its C2 endpoints. Stolen data is POSTed to attacker-controlled infrastructure at api.348672-shakepay.com over HTTPS with silent error handling to avoid triggering investigation.
#0010
Socketabout 1 month ago9 min▣LLM reportcritical A compromised developer GitHub account was used to inject credential-stealing functionality into @injectivelabs/sdk-ts version 1.20.21, a popular npm package with ~50,000 weekly downloads. The malicious code hooks the fromMnemonic and fromHex functions to capture wallet private keys and mnemonic phrases, then exfiltrates them via POST requests to an abused InjectiveLabs infrastructure endpoint. The threat actor amplified impact by publishing 17 additional @injectivelabs scoped packages at version 1.20.21, all pinned to the malicious SDK version.
#0011
Socketabout 1 month ago15 min▣LLM reporthigh Operation Muck and Load is a supply chain attack campaign centered on a malicious Go module that impersonates a DNS scanner tool to deliver a multi-stage Windows malware loader. The campaign leverages 222 GitHub lure repositories across 190 accounts with automated commit-farming workflows to create false credibility, and uses public dead-drop resolvers across multiple platforms for resilient payload-location resolution. The final payload chain delivers AsyncRAT, Quasar, Remcos, Vidar infostealer, and cryptominers through password-protected 7z archives extracted into masqueraded Microsoft-themed directories.
#0012
Socketabout 1 month ago12 min▣LLM reporthigh A coordinated supply-chain campaign published 17 typosquatted npm and PyPI packages mimicking PaySafe, Skrill, and Neteller payment SDKs. The packages implement a fake SDK facade that harvests environment variables containing credentials and tokens, then exfiltrates them over HTTPS to an ngrok-based C2 server. The malware includes sandbox evasion logic and multi-layer C2 domain obfuscation to hinder analysis.
#0013
Socketabout 2 months ago16 min▣LLM reportcritical A new wave of the Mini Shai-Hulud/Miasma/Hades supply chain attack campaign has compromised 23 npm packages across the LeoPlatform and RStreams ecosystems, plus the Verana Blockchain Go module. The attack uses binding.gyp install-time execution (Phantom Gyp pattern) to trigger multi-stage obfuscated JavaScript loaders that decrypt AES-GCM payloads, stage execution through Bun to evade Node.js security hooks, and steal developer/CI/CD credentials including npm, GitHub, cloud, and AI-agent tokens. The campaign also poisons GitHub Actions workflows and plants persistence hooks in AI coding assistant configurations, creating delayed execution surfaces that survive package remediation.
#0014
Socketabout 2 months ago11 min▣LLM reporthigh Malicious Chrome and Firefox browser extensions masquerading as free VPN tools ('VPN Go: Free VPN') were distributed via official extension marketplaces and later updated to include clipboard-stealing functionality. The extensions monitor clipboard contents on a timer, chunk copied text into ~1000-character segments, and exfiltrate data via HTTP GET requests to hardcoded attacker-controlled IP addresses using a /html/continue.php endpoint with uid, part, total, and data query parameters. Both extensions share infrastructure, code patterns, and build artifacts, confirming a common threat actor. The staged update pattern—initial versions functioning as legitimate proxy tools with later versions adding clipboard theft—highlights the risk of extension update supply chain compromise.
#0015
Socketabout 2 months ago17 min▣LLM reporthigh The Miasma Mini Shai-Hulud supply chain campaign has expanded to compromise 22 npm package versions under the @immobiliarelabs scope, targeting Backstage plugins for GitLab integration and LDAP authentication. The malicious packages use a binding.gyp 'Phantom Gyp' trick to execute hidden root-level index.js payloads without preinstall/postinstall hooks, followed by AES-128-GCM decryption and multi-stage delivery under the Bun runtime. The final payload exfiltrates developer and CI/CD secrets via the GitHub API to attacker-controlled repositories, and the campaign likely propagated through a compromised codfish/semantic-release-action GitHub Action that enabled access to release automation credentials.
#0016
Socket2 months ago7 min▣LLM reportcritical A coordinated supply chain attack compromised over 140 npm packages in the Mastra namespace by injecting a typosquatted dependency, easy-day-js. This dependency uses a postinstall hook to execute a cross-platform Node.js infostealer that establishes persistence, inventories cryptocurrency wallets, steals browser history, and enables arbitrary remote code execution via a custom ICAP-style C2 protocol.
#0017
Socket2 months ago5 min▣LLM reportmedium An npm package named shai_hulululud was discovered utilizing adversarial techniques to disrupt AI-assisted malware scanners. The package employs prompt injection, safety-triggering content, and context flooding via millions of tokens to cause LLM-based analysis tools to fail, truncate, or refuse processing before reaching the obfuscated JavaScript payload.
#0018
Socket2 months ago6 min▣LLM reporthigh Threat researchers discovered GlassWASM, a WebAssembly-based malware distributed via trojanized extensions on the Open VSX marketplace. The malware uses ChaCha20 encryption to evade static analysis and leverages the Solana blockchain as a resilient C2 dead-drop to retrieve and execute OS-specific second-stage payloads via Node.js.
#0019
Socket2 months ago7 min▣LLM reporthigh A fast-moving supply chain campaign dubbed Mini Shai-Hulud/Miasma is targeting Python developers via malicious PyPI wheels. The threat actors are utilizing novel execution techniques, including trojanized native extensions and split-loader .pth hooks that search sys.path for payloads, to deploy the Hades stealer and harvest credentials from CI/CD pipelines and developer workstations.
#0020
Socket2 months ago7 min▣LLM reportcritical A coordinated supply chain attack compromised 19 PyPI packages, utilizing malicious .pth files to achieve execution at Python startup. The loader downloads the Bun runtime to execute an obfuscated JavaScript stealer targeting developer secrets, cloud credentials, and CI/CD tokens, exfiltrating data via GitHub repositories and Actions.