Socket Firewall free install-time malicious package blocker for npm, Python, and Rust
Security Tool/Service
Summary
Hide ▲
Show ▼
Socket released Socket Firewall, a free tool that blocks malicious packages at install time across npm, Python, and Rust, reducing supply-chain risk for developers. The service matters because it also intercepts malicious transitive dependencies, not just top-level packages.
Related Happenings
Packagist package.json hook supply chain attack campaign
Campaign
H score39
First: 23.05.2026 19:07
Last: 23.05.2026 19:07
Sources 1
About this happening:
A coordinated supply chain attack campaign compromised eight Packagist packages, creating repeat execution risk for projects that install the affected versions. The malici...
Packagist package.json hook supply chain attack campaign
CampaignAbout this happening: A coordinated supply chain attack campaign compromised eight Packagist packages, creating repeat execution risk for projects that install the affected versions. The malici...
Deadcode09284814 malicious npm packages delivering Phantom Bot and infostealers
Malware Activity
H score22
First: 18.05.2026 11:57
Last: 18.05.2026 11:57
Sources 1
About this happening:
Four npm packages published by deadcode09284814 were found delivering information-stealing malware and Phantom Bot DDoS capability, putting installers at risk of *...
Deadcode09284814 malicious npm packages delivering Phantom Bot and infostealers
Malware ActivityAbout this happening: Four npm packages published by deadcode09284814 were found delivering information-stealing malware and Phantom Bot DDoS capability, putting installers at risk of *...
Inactive maintainer account 'atiertant' hit by network compromise
Incident
H score13
First: 15.05.2026 20:10
Last: 15.05.2026 20:10
Sources 1
About this happening:
The inactive maintainer account 'atiertant' for node-ipc was compromised, enabling malicious package releases that could steal credentials from downstream installation...
Inactive maintainer account 'atiertant' hit by network compromise
IncidentAbout this happening: The inactive maintainer account 'atiertant' for node-ipc was compromised, enabling malicious package releases that could steal credentials from downstream installation...
Mini Shai-Hulud npm supply-chain malware wave
Malware Activity
H score68
First: 12.05.2026 14:07
Last: 12.05.2026 14:07
Sources 1
About this happening:
The Mini Shai-Hulud npm malware activity now includes the Miasma variant affecting Microsoft GitHub repositories in a self-replicating supply-chain campaign. O...
Mini Shai-Hulud npm supply-chain malware wave
Malware ActivityAbout this happening: The Mini Shai-Hulud npm malware activity now includes the Miasma variant affecting Microsoft GitHub repositories in a self-replicating supply-chain campaign. O...
Latest development: 09.06.2026 18:42
On June 5, Microsoft removed 73 repositories across its Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on GitHub after concerns about potential malicious content tied to the Miasma/Shai-Hulud supply-chain campaign. The action disrupted continuous integration pipelines and broke workflows that depended on Azure/functions-action, while Microsoft said it temporarily removed some repositories during its investigation.
BufferZoneCorp sleeper-package supply chain campaign
Campaign
H score38
First: 01.05.2026 12:43
Last: 01.05.2026 12:43
Sources 1
About this happening:
The BufferZoneCorp software supply chain campaign is pushing malicious Ruby gems and Go modules that can steal credentials, tamper with GitHub Actions, and persist on...
BufferZoneCorp sleeper-package supply chain campaign
CampaignAbout this happening: The BufferZoneCorp software supply chain campaign is pushing malicious Ruby gems and Go modules that can steal credentials, tamper with GitHub Actions, and persist on...
Timeline
-
02.10.2025 16:07 2 articles · 9mo ago
Socket releases Socket Firewall for install-time malicious package blocking
Mitigation Patch UpdateSocket released Socket Firewall, a free tool that blocks malicious packages at install time across npm, Python, and Rust ecosystems. The tool also prevents package managers from fetching malicious transitive dependencies, extending protection beyond top-level packages in developer installation workflows.
Show sources
- Alert: Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown — thehackernews.com — 02.10.2025 16:07
- Alert: Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown — thehackernews.com — 02.10.2025 16:07