Socket Security (socket.dev blog)
socket-dev-blog · B · active
Primary disclosure outlet for supply-chain security findings (TeamPCP/Mini Shai-Hulud, node-ipc, GemStuffer). Multiple in-window primaries in W21 run. Proposed by W1 sub-agent. | 2026-05-26: contributed TrapDoor + Packagist supply-chain primaries (S1, S3). | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://socket.dev/blog (listing) then webfetch the per-article socket.dev/blog/<slug> URL for body (full technical analysis renders). AVOID: Nothing to avoid; plain WebFetch works on listing and article. Listing mixes product-announcement posts (Socket MCP/Firewall) with the supply-chain research, filter to the package-compromise titles.. | 2026-07-05 admiralty audit: B, original supply-chain research from own scanning telemetry; reputable vendor lab. No status change (active). | 2026-10-02 (2026-10-02T0404Z-intel): the listing is a Next.js page; `url` or `extract` raw HTML carries a JSON blob with title, date and url per post (regex on the escaped keys).
Cited in 7 entries
Citation cadence
Citation days per ISO week (6 weeks of coverage span, total 7).
- Mastra npm supply-chain compromise (easy-day-js)2026-06-18
- TeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivative2026-06-09
- "Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse2026-06-02
- "TrapDoor" cross-ecosystem supply-chain campaign validates stolen tokens before exfil and poisons AI-assistant config files2026-05-26
- Packagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strand2026-05-24
- node-ipc npm package backdoored via expired-domain account takeover, 90+ credential categories exfiltrated, three malicious versions, ~3-minute window to detection2026-05-16
- GemStuffer, an OpenAI autonomous-agent swarm gained RCE on RubyGems' companion documentation-build service RubyDoc.info, then tried to steal other users' API keys, and OpenAI never reported it under the EU AI Act2026-05-14