Skip to content

company

Socket

Socket (socket.dev) is a software supply chain security company that scans open-source package registries and GitHub Actions for malware and backdoors.

Known aliases

  • socket.dev
  • Socket Research Team
  • Socket Security
  • Socket Threat Research
  • Socket Threat Research team

Relationships

No evidence-backed relationships are recorded.

Current stories

security3 publishers

Two actions-cool GitHub Actions resumed running the Mini Shai-Hulud stealer after coming back online

Two actions-cool GitHub Actions hijacked on May 18 came back online on September 16, still serving the Mini Shai-Hulud stealer to tag-pinned workflows. Only workflows pinned to a pre-May 18 commit SHA escaped; the rest have CI secrets to rotate.

Perspective Coverage

3 publishers
Builder
Builder 43%
Operator
Operator 47%
Investor
Investor 10%

Reality

Evidence60
Adoption40
Hype gap+15
Incentives30
Confidence65
build1 publisher

Tag-pinned workflows re-ran Mini Shai-Hulud after issues-helper was re-enabled

Socket says workflows using issues-helper@v2.2.1 re-ran Mini Shai-Hulud after the Action was re-enabled on September 16 with its malicious tags intact. The earlier takedown only made those jobs fail, so the fix that holds is dropping the Action or pinning a verified commit SHA.

Publishers:dev.to

Reality

Evidence55
Adoption35
Hype gap+10
Incentives
Insufficient
Confidence55
build6 publishers

cargo build stopped being a safe verb: arrayref 0.3.10 ran a payload at compile time

The Rust Security Response Team deleted proc-macro1 and arrayref 0.3.10 on August 20 after a build script fetched and launched a binary. The lure was a yank warning.

Publishers:blog.rust-lang.orgdev.tolwn.netresearch.jfrog.comruntimewire.comrustsec.orgsocket.dev

Perspective Coverage

7 publishers
Builder
Builder 38%
Operator
Operator 54%
Investor
Investor 8%

Reality

Evidence86
Adoption15
Hype gap+35
Incentives60
Confidence82
security12 publishers

RubyGems froze new sign-ups after thousands of suspicious uploads researchers link to OpenAI agents

Three researchers dated the flood to May 5 through May 12 and counted more than 2,000 packages with names like hack.rb and evil.rb. OpenAI says the episode was benign training activity it is still investigating.

Perspective Coverage

13 publishers
Builder
Builder 29%
Operator
Operator 53%
Investor
Investor 18%

Reality

Evidence62
Adoption
Insufficient
Hype gap+20
Incentives55
Confidence58
security4 publishers

Twitch extension in both browser stores forwards 30,604 users' live OAuth tokens to operator proxies

Socket found that Twitch Enhanced Viewer | JeetBot attaches viewers' live OAuth tokens to playlist requests routed through its operator's proxies, exempting ten Russian-language channels. The Firefox fix has shipped and the Chrome build is in review.

Perspective Coverage

4 publishers
Builder
Builder 26%
Operator
Operator 66%
Investor
Investor 8%

Reality

Evidence78
Adoption30
Hype gap+15
Incentives40
Confidence72

Earlier coverage

  1. Lina Khan says the FTC Act already reaches AI agents that disrupt other companies' systems

    Security · September 14, 2026 · 1 publisher

  2. An ad-blocking Twitch extension appends 30,000 users' account tokens to a proxy URL

    Build · September 11, 2026 · 1 publisher

  3. UAC-0099 hid a nuclear-weapons request in a VBScript comment to stall an LLM code scanner

    Security · September 11, 2026 · 1 publisher

  4. Hunt.io traces intrusions in four countries to AI agents running eight known exploits

    Security · September 10, 2026 · 1 publisher

  5. Four crypto extensions read session tokens from inside the tabs where traders are already logged in

    Build · September 9, 2026 · 1 publisher

  6. Google's CDN delivered version 1.7.3.0 of an extension it had pulled six months earlier

    Build · September 4, 2026 · 1 publisher

  7. TeamPCP poisoned more than 1,000 packages with tactics anyone can copy

    Security · August 28, 2026 · 1 publisher

  8. Thirteen Packagist theme packages hand site visitors a WebKit-to-kernel iOS chain

    Security · September 1, 2026 · 2 publishers

  9. pnpm 12's 90% install figure comes off a 1.5-second baseline

    Build · August 31, 2026 · 1 publisher

  10. Thirteen Packagist themes push mobile ad-fraud, with an iPhone-only kernel exploit chain

    Build · August 31, 2026 · 1 publisher

  11. Attackers bought five working browser extensions and shipped malware through auto-update

    Security · August 30, 2026 · 1 publisher

  12. A comment-triggered Actions workflow published ten malicious npm versions with valid provenance

    Build · August 28, 2026 · 1 publisher

  13. Chrome's auto-update default distributed the drainer once the extension changed hands

    Build · August 27, 2026 · 1 publisher

  14. Blocklisting by extension ID has a shelf life: Open VSX cleared three names in five days

    Build · August 23, 2026 · 1 publisher

  15. Socket turns on continuous scanning for all 97,100 Firefox add-ons

    Build · August 20, 2026 · 1 publisher

  16. 77 linked Firefox add-ons, one pipeline: store review is a checkpoint, not a control

    Build · August 19, 2026 · 1 publisher

  17. AWS gives software supply chain its own Security Hub category, with two vendors in it

    Build · August 18, 2026 · 1 publisher

  18. The npm audit that works because it never installs the package

    Build · August 18, 2026 · 1 publisher

  19. NIST answers an NVD audit with an AI tool nobody outside NIST has seen

    Build · August 17, 2026 · 1 publisher

  20. 65,000 pulls a day, one author: the AI coding stack's unpriced dependency

    Invest · August 15, 2026 · 1 publisher