Socket
Socket
Sign inDemoInstall

Secure your dependencies. Ship with confidence.

Socket is a developer-first security platform that protects your code from both vulnerable and malicious dependencies.

Install GitHub AppBook a Demo

Protecting the best engineering teams in the world

Find and compare millions of open source packages

Quickly evaluate the security and health of any open source package.

react


react-bot published 18.3.1 •
jquery


timmywil published 3.7.1 •
left-pad


stevemao published 1.3.0 •

We protect you from vulnerable and malicious packages

itfd

1.0.0

by vector0x1

Removed from npm

Blocked by Socket

This script downloads content from 'https://4dii5lvq33941h0b63exuyh35ublzbn0.oastify.com'. This is considered suspicious and could be a sign of a malicious actor attempting to exploit a vulnerability in the system.

Live on npm for 2 days, 4 hours and 29 minutes before removal. Socket users were protected even while the package was live.

@ssr-frontend/packages-analytics

99.10.22

by ssr-frontend

Live on npm

Blocked by Socket

This code collects sensitive information (user, host, pwd, directory structure, and file contents) and sends it to a remote server without user consent. This behavior is highly suspicious and suggests potential data exfiltration.

usaa-combobox

1.0.0

by brugninho

Removed from npm

Blocked by Socket

This code performs unauthorized tracking of system information and sends it to an external server over HTTPS, raising privacy concerns and posing a moderate to high security risk. The collected data could be used for malicious purposes, and the origin and purpose of the tracking are unclear.

Live on npm for 7 hours and 2 minutes before removal. Socket users were protected even while the package was live.

monitoring_ceo_test

2.999.0

by testtest01

Removed from npm

Blocked by Socket

The code is highly suspicious due to its obfuscation and execution of a hidden script. This behavior is consistent with malware practices, posing a significant security risk.

Live on npm for 2 hours and 11 minutes before removal. Socket users were protected even while the package was live.

prize-market

3.999.0

by 0xnaeem

Removed from npm

Blocked by Socket

The code is performing potentially malicious activities by collecting and exfiltrating system information to an external domain. This poses a significant security risk.

Live on npm for 44 minutes before removal. Socket users were protected even while the package was live.

epm-rdpt-angularjs

1.1.4

by nishant57

Removed from npm

Blocked by Socket

The code establishes a reverse shell connection to a remote server, which is a severe security risk. This allows remote command execution and control over the affected system.

Live on npm for 24 minutes before removal. Socket users were protected even while the package was live.

@swenkerorg/quam-minus

0.0.1-security

Removed from npm

Blocked by Socket

This package was removed from the npm registry for security reasons.

Live on npm for 2 hours before removal. Socket users were protected even while the package was live.

notepadplusplus-keybindings

1.0.7

by aswinthambi

Removed from npm

Blocked by Socket

This module sends a GET request to the specified URL. The purpose of this request is unknown and could be used for malicious purposes.

Live on npm for 7 minutes before removal. Socket users were protected even while the package was live.

gulpclan-css

1.2.0

by 17b4a931

Removed from npm

Blocked by Socket

This code poses a serious security risk and should not be used.

Live on npm for 44 minutes before removal. Socket users were protected even while the package was live.

abdo-obfuscate

4.5.1

by AbdelrahmanAhmed

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

@pagseguro/ps-requests-ws

7.5.5

Removed from npm

Blocked by Socket

The script collects information like hostname, username and public IP address and sends it to a remote server.

Live on npm for 4 days, 7 hours and 16 minutes before removal. Socket users were protected even while the package was live.

localcert

1.2.6

by chriswiegman

Removed from npm

Blocked by Socket

The code exhibits significant security risks related to privilege escalation and command injection vulnerabilities. Proper input validation and secure command execution practices are necessary to mitigate these risks.

curri-slack

14.11.1000

Removed from npm

Blocked by Socket

The code exhibits clear malicious behavior by collecting and sending sensitive user information to external servers without consent. The presence of an infinite loop and the sending of 'package.json' contents further indicate a high risk of data theft and potential misuse.

Live on npm for 4 minutes before removal. Socket users were protected even while the package was live.

ufx-ui-root

99.10.10

Removed from npm

Blocked by Socket

The code engages in potentially malicious behavior by collecting sensitive system information and sending it to a remote server without clear user consent. The hard-coded domain, data obfuscation, and lack of transparency raise significant privacy and security concerns. The risk score is high due to the invasive nature of the code.

Live on npm for 28 minutes before removal. Socket users were protected even while the package was live.

azure-confidential-ledger

99.10.9

Removed from npm

Blocked by Socket

The code exhibits clear signs of malicious behavior involving data theft and exfiltration. It encodes and sends sensitive system and user data to a suspicious domain via both DNS queries and HTTPS POST requests.

Live on npm for 35 minutes before removal. Socket users were protected even while the package was live.

github-artifact-exporter-core

3.0.0

by evlisu

Removed from npm

Blocked by Socket

The code is malicious as it extracts sensitive information from the system and sends it to an external, suspicious server. This behavior is characteristic of a data exfiltration attempt.

Live on npm for 17 hours and 32 minutes before removal. Socket users were protected even while the package was live.

dupack

0.0.4

by pinbib

Removed from npm

Blocked by Socket

The code is a CLI tool that manages DuScript and DuSharp languages. It has some security risks and potential vulnerabilities due to dynamic execution, file operations based on user input, and potential input validation issues. Proper input validation, sanitization, and security practices should be implemented.

Live on npm for 14 minutes before removal. Socket users were protected even while the package was live.

chartfactor

4.1.40

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

flask-mongoengin-2

1.0.6

Removed from pypi

Blocked by Socket

The code poses a significant security risk due to the potential for arbitrary code execution and command injection vulnerabilities. It should be reviewed and refactored to remove these security risks. The presence of these functions also raises concerns about potential malicious behavior, warranting further investigation and mitigation.

Live on pypi for 19 days, 19 hours and 23 minutes before removal. Socket users were protected even while the package was live.

to-primitive

99.10.13

by 7yozcnd0

Removed from npm

Blocked by Socket

The code is designed to exfiltrate sensitive system and network information to an external server. The conditions in `isValid` and use of specific encoding functions suggest a deliberate attempt to hide the true nature and selectively activate this behavior, indicative of a malware-like payload.

Live on npm for 3 minutes before removal. Socket users were protected even while the package was live.

bobjoll

9.643.3

by hfrpik

Live on npm

Blocked by Socket

The code appears to be obfuscated and has several unusual patterns and hardcoded values. It sends a POST request to a remote server with data encoded in base64. The purpose of this request is not clear and could potentially be malicious. Further investigation and analysis are recommended.

ys-mozi-metrics

1.0.3

by sys71m

Removed from npm

Blocked by Socket

The script performs a DNS lookup to a domain that includes the current user's username, which raises concerns about data exfiltration and potential malicious intent.

Live on npm for 1 hour and 9 minutes before removal. Socket users were protected even while the package was live.

youtrack-personal-timetracking

99.10.10

Removed from npm

Blocked by Socket

The code engages in potentially malicious behavior by collecting sensitive system information and sending it to a remote server without clear user consent. The hard-coded domain, data obfuscation, and lack of transparency raise significant privacy and security concerns. The risk score is high due to the invasive nature of the code.

Live on npm for 20 minutes before removal. Socket users were protected even while the package was live.

wbpac-hot-middwleware

1.2.0

by 17b4a931

Removed from npm

Blocked by Socket

This code poses a serious security risk and should not be used.

Live on npm for 2 hours and 22 minutes before removal. Socket users were protected even while the package was live.

@dobux/hooks

1.3.7

by dobux

Live on npm

Blocked by Socket

The reports lack concrete evidence to support the claims of malicious behavior and high security risk. The obfuscated nature of the code may have led to misinterpretations. The malware and security risk scores are not justified based on the code provided. Further analysis and clarification are needed to accurately assess the security risks.

itfd

1.0.0

by vector0x1

Removed from npm

Blocked by Socket

This script downloads content from 'https://4dii5lvq33941h0b63exuyh35ublzbn0.oastify.com'. This is considered suspicious and could be a sign of a malicious actor attempting to exploit a vulnerability in the system.

Live on npm for 2 days, 4 hours and 29 minutes before removal. Socket users were protected even while the package was live.

@ssr-frontend/packages-analytics

99.10.22

by ssr-frontend

Live on npm

Blocked by Socket

This code collects sensitive information (user, host, pwd, directory structure, and file contents) and sends it to a remote server without user consent. This behavior is highly suspicious and suggests potential data exfiltration.

usaa-combobox

1.0.0

by brugninho

Removed from npm

Blocked by Socket

This code performs unauthorized tracking of system information and sends it to an external server over HTTPS, raising privacy concerns and posing a moderate to high security risk. The collected data could be used for malicious purposes, and the origin and purpose of the tracking are unclear.

Live on npm for 7 hours and 2 minutes before removal. Socket users were protected even while the package was live.

monitoring_ceo_test

2.999.0

by testtest01

Removed from npm

Blocked by Socket

The code is highly suspicious due to its obfuscation and execution of a hidden script. This behavior is consistent with malware practices, posing a significant security risk.

Live on npm for 2 hours and 11 minutes before removal. Socket users were protected even while the package was live.

prize-market

3.999.0

by 0xnaeem

Removed from npm

Blocked by Socket

The code is performing potentially malicious activities by collecting and exfiltrating system information to an external domain. This poses a significant security risk.

Live on npm for 44 minutes before removal. Socket users were protected even while the package was live.

epm-rdpt-angularjs

1.1.4

by nishant57

Removed from npm

Blocked by Socket

The code establishes a reverse shell connection to a remote server, which is a severe security risk. This allows remote command execution and control over the affected system.

Live on npm for 24 minutes before removal. Socket users were protected even while the package was live.

@swenkerorg/quam-minus

0.0.1-security

Removed from npm

Blocked by Socket

This package was removed from the npm registry for security reasons.

Live on npm for 2 hours before removal. Socket users were protected even while the package was live.

notepadplusplus-keybindings

1.0.7

by aswinthambi

Removed from npm

Blocked by Socket

This module sends a GET request to the specified URL. The purpose of this request is unknown and could be used for malicious purposes.

Live on npm for 7 minutes before removal. Socket users were protected even while the package was live.

gulpclan-css

1.2.0

by 17b4a931

Removed from npm

Blocked by Socket

This code poses a serious security risk and should not be used.

Live on npm for 44 minutes before removal. Socket users were protected even while the package was live.

abdo-obfuscate

4.5.1

by AbdelrahmanAhmed

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

@pagseguro/ps-requests-ws

7.5.5

Removed from npm

Blocked by Socket

The script collects information like hostname, username and public IP address and sends it to a remote server.

Live on npm for 4 days, 7 hours and 16 minutes before removal. Socket users were protected even while the package was live.

localcert

1.2.6

by chriswiegman

Removed from npm

Blocked by Socket

The code exhibits significant security risks related to privilege escalation and command injection vulnerabilities. Proper input validation and secure command execution practices are necessary to mitigate these risks.

curri-slack

14.11.1000

Removed from npm

Blocked by Socket

The code exhibits clear malicious behavior by collecting and sending sensitive user information to external servers without consent. The presence of an infinite loop and the sending of 'package.json' contents further indicate a high risk of data theft and potential misuse.

Live on npm for 4 minutes before removal. Socket users were protected even while the package was live.

ufx-ui-root

99.10.10

Removed from npm

Blocked by Socket

The code engages in potentially malicious behavior by collecting sensitive system information and sending it to a remote server without clear user consent. The hard-coded domain, data obfuscation, and lack of transparency raise significant privacy and security concerns. The risk score is high due to the invasive nature of the code.

Live on npm for 28 minutes before removal. Socket users were protected even while the package was live.

azure-confidential-ledger

99.10.9

Removed from npm

Blocked by Socket

The code exhibits clear signs of malicious behavior involving data theft and exfiltration. It encodes and sends sensitive system and user data to a suspicious domain via both DNS queries and HTTPS POST requests.

Live on npm for 35 minutes before removal. Socket users were protected even while the package was live.

github-artifact-exporter-core

3.0.0

by evlisu

Removed from npm

Blocked by Socket

The code is malicious as it extracts sensitive information from the system and sends it to an external, suspicious server. This behavior is characteristic of a data exfiltration attempt.

Live on npm for 17 hours and 32 minutes before removal. Socket users were protected even while the package was live.

dupack

0.0.4

by pinbib

Removed from npm

Blocked by Socket

The code is a CLI tool that manages DuScript and DuSharp languages. It has some security risks and potential vulnerabilities due to dynamic execution, file operations based on user input, and potential input validation issues. Proper input validation, sanitization, and security practices should be implemented.

Live on npm for 14 minutes before removal. Socket users were protected even while the package was live.

chartfactor

4.1.40

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

flask-mongoengin-2

1.0.6

Removed from pypi

Blocked by Socket

The code poses a significant security risk due to the potential for arbitrary code execution and command injection vulnerabilities. It should be reviewed and refactored to remove these security risks. The presence of these functions also raises concerns about potential malicious behavior, warranting further investigation and mitigation.

Live on pypi for 19 days, 19 hours and 23 minutes before removal. Socket users were protected even while the package was live.

to-primitive

99.10.13

by 7yozcnd0

Removed from npm

Blocked by Socket

The code is designed to exfiltrate sensitive system and network information to an external server. The conditions in `isValid` and use of specific encoding functions suggest a deliberate attempt to hide the true nature and selectively activate this behavior, indicative of a malware-like payload.

Live on npm for 3 minutes before removal. Socket users were protected even while the package was live.

bobjoll

9.643.3

by hfrpik

Live on npm

Blocked by Socket

The code appears to be obfuscated and has several unusual patterns and hardcoded values. It sends a POST request to a remote server with data encoded in base64. The purpose of this request is not clear and could potentially be malicious. Further investigation and analysis are recommended.

ys-mozi-metrics

1.0.3

by sys71m

Removed from npm

Blocked by Socket

The script performs a DNS lookup to a domain that includes the current user's username, which raises concerns about data exfiltration and potential malicious intent.

Live on npm for 1 hour and 9 minutes before removal. Socket users were protected even while the package was live.

youtrack-personal-timetracking

99.10.10

Removed from npm

Blocked by Socket

The code engages in potentially malicious behavior by collecting sensitive system information and sending it to a remote server without clear user consent. The hard-coded domain, data obfuscation, and lack of transparency raise significant privacy and security concerns. The risk score is high due to the invasive nature of the code.

Live on npm for 20 minutes before removal. Socket users were protected even while the package was live.

wbpac-hot-middwleware

1.2.0

by 17b4a931

Removed from npm

Blocked by Socket

This code poses a serious security risk and should not be used.

Live on npm for 2 hours and 22 minutes before removal. Socket users were protected even while the package was live.

@dobux/hooks

1.3.7

by dobux

Live on npm

Blocked by Socket

The reports lack concrete evidence to support the claims of malicious behavior and high security risk. The obfuscated nature of the code may have led to misinterpretations. The malware and security risk scores are not justified based on the code provided. Further analysis and clarification are needed to accurately assess the security risks.

Detect and block software supply chain attacks

Socket detects traditional vulnerabilities (CVEs) but goes beyond that to scan the actual code of dependencies for malicious behavior. It proactively detects and blocks 70+ signals of supply chain risk in open source code, for comprehensive protection.

Possible typosquat attack

Known malware

Git dependency

GitHub dependency

AI-detected potential malware

HTTP dependency

Obfuscated code

NPM Shrinkwrap

Suspicious Stars on GitHub

Telemetry

19 more alerts

Detect suspicious package updates in real-time

Socket detects and blocks malicious dependencies, often within just minutes of them being published to public registries, making it the most effective tool for blocking zero-day supply chain attacks.

GitHub app screenshot

Developers love Socket

Socket is built by a team of prolific open source maintainers whose software is downloaded over 1 billion times per month. We understand how to build tools that developers love. But don’t take our word for it.

Even more developer love

Security teams trust Socket

The best security teams in the world use Socket to get visibility into supply chain risk, and to build a security feedback loop into the development process.

Even more security team love
Book a DemoLearn more

Why teams choose Socket

Pro-active security

Depend on Socket to prevent malicious open source dependencies from infiltrating your app.

Easy to install

Install the Socket GitHub App in just 2 clicks and get protected today.

Comprehensive open source protection

Block 70+ issues in open source code, including malware, typo-squatting, hidden code, misleading packages, permission creep, and more.

Develop faster

Reduce work by surfacing actionable security information directly in GitHub. Empower developers to make better decisions.

Supply chain attacks are on the rise

Attackers have taken notice of the opportunity to attack organizations through open source dependencies. Supply chain attacks rose a whopping 700% in the past year, with over 15,000 recorded attacks.

Dec 14, 2023

Hijacked cryptocurrency library adds malware

Widely-used library in cryptocurrency frontend was compromised to include wallet-draining code, following the hijacking of NPM account credentials via phishing.

Jan 06, 2022

Maintainer intentionally adds malware

Rogue maintainer sabotages his own open source package with 100M downloads/month, notably breaking Amazon's AWS SDK.

Nov 15, 2021

npm discovers a platform vulnerability allowing unauthorized publishing of any package

Attackers could publish new versions of any npm package without authorization for multiple years.

Oct 22, 2021

Hijacked package adds cryptominers and password-stealing malware

Multiple packages with 30M downloads/month are hijacked and publish malicious versions directly into the software supply chain.

Nov 26, 2018

Package hijacked adding organization specific backdoors

Obfuscated malware added to a dependency which targeted a single company, went undetected for over a week, and made it into their production build.

Ready to dive in?

Get protected by Socket with just 2 clicks.

Install GitHub AppBook a Demo

The latest from the Socket team

Get our latest security research, open source insights, and product updates.

View all articles
SocketSocket SOC 2 Logo

Product

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc