Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
|
from
login
Open VSX Sleeper Extensions Linked to GlassWorm Show New Malware Activations
(
socket.dev
)
1 point
by
salkahfi
1 day ago
|
past
|
discuss
Introducing Data Exports
(
socket.dev
)
1 point
by
ilreb
2 days ago
|
past
|
discuss
Malicious Checkmarx Artifacts Found in Official KICS Docker Repository
(
socket.dev
)
1 point
by
darkwater
2 days ago
|
past
|
discuss
Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
(
socket.dev
)
862 points
by
tosh
2 days ago
|
past
|
420 comments
Malicious Checkmarx Artifacts Found in Official KICS Docker Repo and Code Ext
(
socket.dev
)
3 points
by
orkj
2 days ago
|
past
|
discuss
Malicious Checkmarx Artifacts Found in Official KICS Docker Repository
(
socket.dev
)
4 points
by
justsomehuman
3 days ago
|
past
|
discuss
108 Chrome Extensions Linked to Data Exfiltration and Session Theft via C2
(
socket.dev
)
6 points
by
jbegley
12 days ago
|
past
|
discuss
Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline
(
socket.dev
)
3 points
by
salkahfi
14 days ago
|
past
|
1 comment
North Korea's Contagious Interview Campaign Spreads Across 5 Ecosystems
(
socket.dev
)
2 points
by
pier25
18 days ago
|
past
Attackers Are Hunting High-Impact Node.js Maintainers with Social Engineering
(
socket.dev
)
3 points
by
pier25
22 days ago
|
past
|
2 comments
Axios Maintainer Confirms Social Engineering Attack Behind NPM Compromise
(
socket.dev
)
5 points
by
feross
23 days ago
|
past
The Hidden Blast Radius of the Axios Compromise
(
socket.dev
)
6 points
by
feross
24 days ago
|
past
Supply Chain Attack on Axios Pulls Malicious Dependency from NPM
(
socket.dev
)
2 points
by
dsr12
25 days ago
|
past
TeamPCP Is Systematically Targeting Security Tools Across the OSS Ecosystem
(
socket.dev
)
5 points
by
pier25
32 days ago
|
past
Trivy Supply Chain Attack Expands to Compromised Docker Images
(
socket.dev
)
5 points
by
feross
34 days ago
|
past
|
3 comments
Trivy under attack again: Widespread GitHub Actions tag compromise secrets
(
socket.dev
)
250 points
by
jicea
34 days ago
|
past
|
83 comments
Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes
(
socket.dev
)
3 points
by
tamnd
35 days ago
|
past
|
1 comment
CanisterWorm: NPM Publisher Compromise Deploys Backdoor Across 29 Packages
(
socket.dev
)
3 points
by
pier25
36 days ago
|
past
Widespread Trivvy GitHub Actions Tag Compromise Exposes CI/CD Secrets
(
socket.dev
)
7 points
by
donutshop
37 days ago
|
past
|
1 comment
Enisa Technical Advisory on Secure Use of Package Managers
(
socket.dev
)
6 points
by
pier25
37 days ago
|
past
Malicious NPM Packages Use Pastebin Steganography to Deploy Credential Stealer
(
socket.dev
)
2 points
by
feross
57 days ago
|
past
Malicious Go "Crypto" Module Steals Passwords and Deploys Rekoobe Backdoor
(
socket.dev
)
3 points
by
feross
58 days ago
|
past
Shai-Hulud-Style NPM Worm Hijacks CI Workflows and Poisons AI Toolchains
(
socket.dev
)
10 points
by
jicea
63 days ago
|
past
Shai-Hulud-Style NPM Worm Hijacks CI Workflows and Poisons AI Toolchains
(
socket.dev
)
8 points
by
feross
64 days ago
|
past
Socket brings supply chain security to skills.sh
(
socket.dev
)
2 points
by
ryoidong
65 days ago
|
past
AI Agent Lands PRs in Major OSS Projects, Targets Maintainers via Cold Outreach
(
socket.dev
)
3 points
by
puppion
67 days ago
|
past
AI Agent Lands PRs in Major OSS Projects
(
socket.dev
)
1 point
by
bradyholt
68 days ago
|
past
AI Agent Lands PRs in Major OSS Projects, Targets Maintainers via Cold Outreach
(
socket.dev
)
2 points
by
choult
69 days ago
|
past
AI Agent Lands PRs in Major OSS Projects, Targets Maintainers via Cold Outreach
(
socket.dev
)
16 points
by
cdrnsf
70 days ago
|
past
|
1 comment
AI Agent Lands PRs in Major OSS Projects
(
socket.dev
)
2 points
by
junon
70 days ago
|
past
More
Consider applying for YC's Summer 2026 batch! Applications are open till May 4
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: