惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Spread Privacy
Spread Privacy
S
Schneier on Security
博客园 - 【当耐特】
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
美团技术团队
Application and Cybersecurity Blog
Application and Cybersecurity Blog
MongoDB | Blog
MongoDB | Blog
NISL@THU
NISL@THU
N
Netflix TechBlog - Medium
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Webroot Blog
Webroot Blog
月光博客
月光博客
T
The Exploit Database - CXSecurity.com
Forbes - Security
Forbes - Security
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 叶小钗
Recent Announcements
Recent Announcements
IT之家
IT之家
B
Blog
C
CERT Recently Published Vulnerability Notes
S
SegmentFault 最新的问题
Recent Commits to openclaw:main
Recent Commits to openclaw:main
F
Fortinet All Blogs
Martin Fowler
Martin Fowler
Know Your Adversary
Know Your Adversary
Security Latest
Security Latest
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
T
Troy Hunt's Blog
O
OpenAI News
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
CXSECURITY Database RSS Feed - CXSecurity.com
V2EX - 技术
V2EX - 技术
L
Lohrmann on Cybersecurity
C
Cyber Attacks, Cyber Crime and Cyber Security
H
Help Net Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Last Week in AI
Last Week in AI
Help Net Security
Help Net Security
Hacker News: Ask HN
Hacker News: Ask HN
A
About on SuperTechFans
Y
Y Combinator Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
Engineering at Meta
Engineering at Meta
T
Threat Research - Cisco Blogs
Vercel News
Vercel News
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Recorded Future
Recorded Future
C
Cisco Blogs
Project Zero
Project Zero

Socket

White House Launches Gold Eagle Initiative to Manage Surge i... Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu... Next.js moves to scheduled security releases - Socket 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windo... Compromised npm Packages in the AsyncAPI Namespace Deliver M... jscrambler npm Package Compromised in Supply Chain Attack - ... Fake Braintree NuGet Package Skims Credit Cards and Harvests... Compromised Injective SDK npm Package Exfiltrates Wallet Key... npm v12 Ships With Install Scripts Off by Default, Begins De... Malicious Go Module Exposes GitHub Malware Lure Network Span... pnpm 11.10 Hardens Registry Authentication to Block Token Re... Coordinated npm and PyPI Campaign Typosquats Popular Secure ... Node.js Considers Public Workflow for Security Reports Amid ... PolinRider: North Korea-Linked Supply Chain Campaign Expands... Risky Biz Podcast: AI Agents Are Raising the Stakes for Soft... Chrome and Firefox Extensions Posing as Free VPNs Add Clipbo... Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages - S... Rolldown Pulls Rust React Compiler Integration After Binary ... Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and Git... Frontier AI Is Now Critical Infrastructure - Socket The Code You Didn't Write Is Still Yours to Defend - Socket GitHub Actions Checkout Now Blocks Risky pull_request_target... Introducing Repository Access Permissions and Custom Roles -... Socket Firewall Now Blocks Malicious VS Code and Open VSX Ex... 140+ Mastra npm Packages Compromised in Coordinated Supply C... npm Package Uses Prompt Injection and Token Flooding to Disr... Introducing Manifest Alerts - Socket GlassWASM: WebAssembly Malware Found in Trojanized Open VSX ... Socket for Linear Is Now Available - Socket US Government Forces Anthropic to Pull Claude Fable Days After Launch 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search Traffic Andrew Becherer Joins Socket as Chief Information Security Officer Socket Partners with Replit to Block Malicious Packages in AI-Powered Development npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems pnpm 11.5 Adds Support for Recognizing npm Staged Publishes pnpm 11.5 Adds Support for Recognizing npm Staged Publishes Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD Backlog Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD Backlog Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages Famous Chollima Targets PHP Developers Through Compromised Packagist Package Famous Chollima Targets PHP Developers Through Compromised Packagist Package Rust Moves to Restrict LLM Use in Contributions After Months of Internal Debate Rust Moves to Restrict LLM Use in Contributions After Months of Internal Debate Malicious NuGet Package Impersonates Sicoob SDK to Exfiltrate Banking Certificates and Passwords Malicious NuGet Package Impersonates Sicoob SDK to Exfiltrate Banking Certificates and Passwords Feross on TBPN: Socket's Series C and the State of Software Supply Chain Security Feross on TBPN: Socket's Series C and the State of Software Supply Chain Security OSV Withdraws 157 Malware Reports After Automated False Positives Hit npm and PyPI OSV Withdraws 157 Malware Reports After Automated False Positives Hit npm and PyPI TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io Laravel Lang Compromised with RCE Backdoor Across 700+ Versions Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects AI Has Taken Over Open Source npm Invalidates Granular Access Tokens as Mini Shai-Hulud Sweeps the Registry Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit Socket raises $60M Series C at $1B valuation led by Thrive Capital to secure AI-driven software development Socket Raises $60M Series C at a $1B Valuation to Help Enterprises Build Securely With AI Popular Go Decimal Library Targeted by Long-Running Typosquat with DNS Backdoor Active Supply Chain Attack Compromises @antv Packages on npm Popular node-ipc npm Package Infected with Credential Stealer TeamPCP and BreachForums Launch $1,000 Contest for Supply Chain Attacks Packagist Urges Immediate Composer Update After GitHub Actions Token Leak GemStuffer Campaign Abuses RubyGems as Exfiltration Channel Targeting UK Local Government Socket Named to Rising in Cyber 2026 List of Top Cybersecurity Startups TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack fsnotify Maintainer Dispute Sparks Supply Chain Concerns Socket Releases Free Certified Patches for Critical vm2 Sandbox Escape 5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer pnpm 11 Adds Supply Chain Protection Defaults for Minimum Release Age and Exotic Subdependencies PyPI Fixes High-Severity Access Control Issues Found in Security Audit Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP Package Follows npm Compromise Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack lightning PyPI Package Compromised in Supply Chain Attack Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables SAP CAP npm Packages Hit by Supply Chain Attack Socket Has Acquired Secure Annex 73 Open VSX Sleeper Extensions Linked to GlassWorm Show New Malware Activations Introducing Reachability for PHP Introducing Data Exports Malicious Checkmarx Artifacts Found in Official KICS Docker Repository and Code Extensions Introducing Organization Notifications in Socket Introducing Reports: An Extensible Reporting Framework for Socket Data Socket for Jira Is Now Available Socket Named Top Sales Organization by RepVue NIST Officially Stops Enriching Most CVEs as Vulnerability Volume Skyrockets Socket Selected for OpenAI's Cybersecurity Grant Program Feross on the 10 Minutes or Less Podcast: Nobody Reads the Code 108 Chrome Extensions Linked to Data Exfiltration and Session Theft via Shared C2 Infrastructure Node.js Drops Bug Bounty Rewards After Funding Dries Up The Hidden Blast Radius of the Axios Compromise
Socket MCP Adds Org Alerts, Threat Feed Review, and Package ...
John Tuckner · 2026-06-19 · via Socket

Sidebar CTA Background

Secure your dependencies with us

Socket proactively blocks malicious open source packages in your code.

Install

AppSec and security engineering teams are under pressure to triage supply chain issues faster, with more context and less manual investigation. A single alert can require checking package metadata, reviewing published files, searching for suspicious code, cross-referencing threat intelligence, and determining whether the package appears anywhere in the organization.

Socket MCP is now bringing that workflow into MCP-aware AI assistants. With authenticated access to Socket APIs, teams can investigate org alerts, inspect package artifacts, review the threat feed, and ask follow-up questions about exposure and risk without jumping between dashboards, registries, and local tooling.

Socket MCP started with real-time package scoring, helping developers and agents evaluate dependencies before adding them to a project. With this update, we’re expanding the server across more of Socket’s APIs, making it useful for both package selection and security triage.

With Socket MCP, teams can now ask an assistant to:

  • Score a dependency before adding it to a project
  • Review open Socket alerts across an organization
  • Check the threat feed for recently flagged malware, typosquats, and obfuscated packages
  • Inspect the files inside a published package before installing it
  • Read or grep package contents for suspicious behavior
  • Connect package-level findings back to org exposure

Socket MCP is designed for the way developers and security teams already work with AI assistants: ask a question, inspect the evidence, and keep the investigation moving without switching between tools or clicking through screens.

From Dependency Scoring to Supply-Chain Investigation#

Socket MCP first launched with real-time package scoring for AI-assisted development. When an assistant suggests a new dependency, `depscore` can check its supply-chain, quality, maintenance, vulnerability, and license scores before the package lands in a manifest.

This update extends that workflow much further.

Socket MCP now exposes seven tools across public and authenticated access tiers:

Capability What it helps you do
Dependency scoring Evaluate package risk across supply chain, quality, maintenance, vulnerability, and license signals.
Package file inspection Review the files included in a published package and inspect the contents that matter.
Package search Search package contents for suspicious strings, imports, symbols, or behavior patterns.
Organization context Look across Socket organizations available to the authenticated user.
Alert triage Review open Socket alerts across projects and packages and begin triaging findings from the assistant.
Threat feed review Review recently flagged malware, typosquats, obfuscated packages, and related threats.

Together, these tools turn Socket MCP into a supply chain security interface for AI assistants.

Ask Questions About Your Organization’s Alerts#

Socket MCP also adds authenticated access to organization-level alerts.

The MCP server can look across any of your Socket organizations, review open alerts across projects and packages, and help begin triaging them from the assistant.

That makes it possible to ask questions like:

  • What critical supply chain alerts are open across our organization?
  • Which repositories are affected by this package?
  • Are there any high-severity alerts involving install scripts?
  • What alerts should we prioritize this week?
  • Do we have any open findings related to this package?

The assistant can group alerts, explain findings in plain language, filter by severity or repository, and connect an alert to package-level investigation tools.

For security teams, this reduces the friction between seeing an alert and understanding the underlying package behavior. For engineering leaders, it creates a faster way to summarize current open-source risk across the organization.

Investigate Packages for Safe Use#

Package metadata only tells part of the story. Malware often hides in install scripts, bundled files, generated JavaScript, encoded payloads, suspicious network calls, or files that are easy to miss during a normal package review.

Socket MCP now supports artifact-level package investigation.

An assistant can look through a published package, surface the files that matter, and explain what it finds alongside Socket’s risk signals. Teams can move beyond package metadata to inspect the actual artifact, understand suspicious behavior, and decide whether a package is safe to use before it enters their environment.

This allows teams to inspect the package that was actually published, without installing it locally.

The workflow applies across supported package ecosystems and extension sources, including npm, PyPI, Maven, Cargo, RubyGems, NuGet, Go, Chrome extensions, and Open VSX / VS Code extensions.

For developers, this makes it easier to vet a dependency or extension before use. For security teams, it provides a fast way to move from a suspicious package name to the files and code paths that matter.

Review the Socket Threat Feed from Your Assistant#

Socket MCP now exposes the Socket threat feed through an authenticated tool.

It can surface recently flagged packages, including malware, typosquats, obfuscated packages, and other suspicious activity. Teams can filter by ecosystem, category, and time window, then ask the assistant to summarize what changed or investigate a specific package in more detail.

Example questions include:

  • What new npm malware was flagged this week?
  • Are there any new typosquats in the ecosystems we use?
  • What recently flagged packages should our team review?
  • Was this package seen in the threat feed?
  • Does this threat appear in our organization’s alerts?

The threat feed becomes more useful when combined with org alerts and package file inspection. A team can identify a newly flagged package, inspect the published files, understand the suspicious behavior, and check whether it appears in their environment in one assistant session.

Score Dependencies Before They Enter Your Codebase#

Socket MCP still supports the original depscore workflow for checking package risk during AI-assisted development. When an assistant suggests a new dependency, it can evaluate supply chain, quality, maintenance, vulnerability, and license scores before the package is added to a project.

Package scoring works through the public hosted Socket MCP server at https://mcp.socket.dev/ with no setup and no token required.

A Single Workflow for Dependency Risk#

The strongest Socket MCP workflows combine multiple tools.

A developer can ask an assistant to choose a package for a new feature. The assistant can score the dependency, compare alternatives, and flag concerns before code changes are made.

A security analyst can start from a Socket alert, inspect the affected package’s files, search for suspicious code, check the threat feed, and determine whether the package appears elsewhere in the organization.

An engineering leader can ask for a plain-language summary of open alerts and recent threat feed activity, with enough detail to understand where follow-up is needed.

These workflows all use the same underlying model: bring Socket’s package intelligence into the assistant, then let the assistant retrieve, connect, and explain the relevant evidence.

Getting Started#

Socket MCP works with MCP-aware assistants and development environments, including Claude, VS Code, Cursor, Windsurf, and other clients that support MCP server configuration.

Connect your assistant to Socket MCP and try scoring a dependency. For organization-specific workflows like alert triage, threat feed review, and exposure investigation, follow the Socket MCP docs to configure authenticated access.

Read the Socket MCP docs, explore the GitHub repo, or connect to the hosted MCP server.