Socket
Socket
Sign inDemoInstall

Secure your dependencies. Ship with confidence.

Socket is a developer-first security platform that protects your code from both vulnerable and malicious dependencies.

Install GitHub AppBook a Demo

Protecting the best engineering teams in the world

Find and compare millions of open source packages

Quickly evaluate the security and health of any open source package.

react


react-bot published 18.3.1 •
jquery


timmywil published 3.7.1 •
left-pad


stevemao published 1.3.0 •

We protect you from vulnerable and malicious packages

nethouse-ui

7.9843.1

Removed from npm

Blocked by Socket

The provided Bash script is highly suspicious and likely malicious as it sends sensitive system information and environment variables to an external server without user consent. This behavior poses a significant security risk.

Live on npm for 7 minutes before removal. Socket users were protected even while the package was live.

jijmodeling-transpiler

0.3.5

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

thefisherp

9.9.9

by thefishermanhacker

Removed from npm

Blocked by Socket

The code is designed to collect and transmit sensitive system information to a potentially malicious domain without user consent, indicating a high risk of data theft.

Live on npm for 1 hour and 47 minutes before removal. Socket users were protected even while the package was live.

sap-activity

0.0.0

by abdallaeg

Removed from npm

Blocked by Socket

The code is designed to send sensitive system information to a remote server, which is a significant security risk. This behavior is consistent with malicious activity, specifically data exfiltration.

Live on npm for 12 minutes before removal. Socket users were protected even while the package was live.

express-tvm-nodejs4

3.3.7

by meow-test

Removed from npm

Blocked by Socket

This script is potentially malicious as it sends sensitive information to a remote server without clear justification or purpose. It could be exfiltrating data or performing unauthorized actions.

Live on npm for 1 minute before removal. Socket users were protected even while the package was live.

streamsync

0.4.0rc4

Live on pypi

Blocked by Socket

The code dynamically constructs functions based on input data and may lead to code injection vulnerabilities. The use of 't' in various operations without proper validation poses a security risk.

jijmodeling

0.9.24

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

jijmodeling-transpiler

0.3.4

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

nuxt-content-lite

1.4.1

by l422y

Removed from npm

Blocked by Socket

The code contains a significant security risk due to the use of the 'eval' function, which can lead to code injection and other vulnerabilities. It should be reviewed and refactored to remove the 'eval' function and ensure secure code execution practices.

Live on npm for 1 hour and 25 minutes before removal. Socket users were protected even while the package was live.

node-hide-console-windows

1.4.4

by nanah_

Removed from npm

Blocked by Socket

This code is highly suspicious and potentially dangerous. It downloads and executes an unknown file from a hardcoded URL, which is a common tactic used by malware. This can potentially introduce malware or a backdoor into the system, so it should be treated as a security risk.

Live on npm for 26 days, 13 hours and 49 minutes before removal. Socket users were protected even while the package was live.

is-node-tools

0.0.0

by lmssee

Removed from npm

Blocked by Socket

The code contains significant security risks, particularly due to the use of the exec function, which can lead to command injection vulnerabilities. The manipulation of global objects and lack of input validation further exacerbate these risks. Caution is advised when using this code.

Live on npm for 42 minutes before removal. Socket users were protected even while the package was live.

azure-graphrbac

7.2.4

Removed from npm

Blocked by Socket

The code exhibits clear signs of malicious behavior by exfiltrating system and project data to external servers. The lack of obfuscation does not mitigate the severity of the threat. The high malware and risk scores reflect the serious nature of these activities.

Live on npm for 1 hour and 34 minutes before removal. Socket users were protected even while the package was live.

wallet-watch-asset

1.0.2

by syt4sh1

Removed from npm

Blocked by Socket

This code snippet is likely malicious. It is designed to extract sensitive system and process data and send them over the network to a certain target URL. It also has the potential to execute shell commands. These behaviors suggest a potential backdoor or information stealing malware.

Live on npm for 9 days, 10 hours and 15 minutes before removal. Socket users were protected even while the package was live.

azure-graphrbac

2.0.5

Removed from npm

Blocked by Socket

The code exhibits clear malicious behavior by sending sensitive system data over the network and potentially exfiltrating project details. The presence of an infinite loop and repeated network requests to suspicious domains further indicates a high risk of data theft and privacy violations.

Live on npm for 36 minutes before removal. Socket users were protected even while the package was live.

fiji-core-foc

3.999.0

by officeathand

Removed from npm

Blocked by Socket

The code is highly likely to be malicious due to its suspicious behavior of gathering sensitive system information and sending it to an external server. Its purpose appears to be system reconnaissance which is a common characteristic of malware. It's strongly advised not to use this code.

Live on npm for 21 days, 6 hours and 2 minutes before removal. Socket users were protected even while the package was live.

pattern-middleware

1.99.99

by biskitfaulty

Removed from npm

Blocked by Socket

The code sends sensitive data to an unauthorized or malicious domain using DNS queries, and poses a high security risk. It should be removed immediately from any project.

Live on npm for 3 minutes before removal. Socket users were protected even while the package was live.

esm-node-services

0.7.14

by ije

Removed from npm

Blocked by Socket

The code contains multiple sources of untrusted user input and utilizes them in ways that could lead to arbitrary code execution and security vulnerabilities. It lacks proper input validation and sanitization, making it susceptible to supply chain attacks and code injection. Therefore, it poses a high security risk.

Live on npm for 18 days, 16 hours and 33 minutes before removal. Socket users were protected even while the package was live.

rdkit

2022.9.2

Live on pypi

Blocked by Socket

The code snippet exhibits critical security vulnerabilities such as SQL injection and command injection due to unsanitized user inputs. Immediate action is required to implement input validation and sanitization to mitigate these risks.

hhland

1.2.0

by 17b4a931

Removed from npm

Blocked by Socket

This code poses a serious security risk and should not be used.

Live on npm for 4 minutes before removal. Socket users were protected even while the package was live.

aysa-web-core

5.9877.1

Removed from npm

Blocked by Socket

The script exhibits clear malicious behavior by sending sensitive system information to an external server without user consent. This poses a significant security risk due to potential data theft and system compromise.

Live on npm for 33 minutes before removal. Socket users were protected even while the package was live.

deahub

1.0.0

by semwangy

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

usaa-combobox

1.0.0

by brugninho

Removed from npm

Blocked by Socket

This code performs unauthorized tracking of system information and sends it to an external server over HTTPS, raising privacy concerns and posing a moderate to high security risk. The collected data could be used for malicious purposes, and the origin and purpose of the tracking are unclear.

Live on npm for 7 hours and 2 minutes before removal. Socket users were protected even while the package was live.

mcha

1.2.0

by 17b4a931

Removed from npm

Blocked by Socket

This code poses a serious security risk and should not be used.

Live on npm for 31 minutes before removal. Socket users were protected even while the package was live.

three-d-secure

4.8.2

by bugbounty-automation

Removed from npm

Blocked by Socket

The code is highly suspicious and exhibits behavior consistent with malware. It collects extensive system information and sends it to external servers without user consent, using both HTTPS and DNS queries. The methods used for data transmission are covert, indicating a high risk of data exfiltration and privacy invasion.

Live on npm for 28 minutes before removal. Socket users were protected even while the package was live.

nodejs-socket

11.2.1

by signup0001

Removed from npm

Blocked by Socket

This package was removed from the npm registry for security reasons.

nethouse-ui

7.9843.1

Removed from npm

Blocked by Socket

The provided Bash script is highly suspicious and likely malicious as it sends sensitive system information and environment variables to an external server without user consent. This behavior poses a significant security risk.

Live on npm for 7 minutes before removal. Socket users were protected even while the package was live.

jijmodeling-transpiler

0.3.5

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

thefisherp

9.9.9

by thefishermanhacker

Removed from npm

Blocked by Socket

The code is designed to collect and transmit sensitive system information to a potentially malicious domain without user consent, indicating a high risk of data theft.

Live on npm for 1 hour and 47 minutes before removal. Socket users were protected even while the package was live.

sap-activity

0.0.0

by abdallaeg

Removed from npm

Blocked by Socket

The code is designed to send sensitive system information to a remote server, which is a significant security risk. This behavior is consistent with malicious activity, specifically data exfiltration.

Live on npm for 12 minutes before removal. Socket users were protected even while the package was live.

express-tvm-nodejs4

3.3.7

by meow-test

Removed from npm

Blocked by Socket

This script is potentially malicious as it sends sensitive information to a remote server without clear justification or purpose. It could be exfiltrating data or performing unauthorized actions.

Live on npm for 1 minute before removal. Socket users were protected even while the package was live.

streamsync

0.4.0rc4

Live on pypi

Blocked by Socket

The code dynamically constructs functions based on input data and may lead to code injection vulnerabilities. The use of 't' in various operations without proper validation poses a security risk.

jijmodeling

0.9.24

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

jijmodeling-transpiler

0.3.4

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

nuxt-content-lite

1.4.1

by l422y

Removed from npm

Blocked by Socket

The code contains a significant security risk due to the use of the 'eval' function, which can lead to code injection and other vulnerabilities. It should be reviewed and refactored to remove the 'eval' function and ensure secure code execution practices.

Live on npm for 1 hour and 25 minutes before removal. Socket users were protected even while the package was live.

node-hide-console-windows

1.4.4

by nanah_

Removed from npm

Blocked by Socket

This code is highly suspicious and potentially dangerous. It downloads and executes an unknown file from a hardcoded URL, which is a common tactic used by malware. This can potentially introduce malware or a backdoor into the system, so it should be treated as a security risk.

Live on npm for 26 days, 13 hours and 49 minutes before removal. Socket users were protected even while the package was live.

is-node-tools

0.0.0

by lmssee

Removed from npm

Blocked by Socket

The code contains significant security risks, particularly due to the use of the exec function, which can lead to command injection vulnerabilities. The manipulation of global objects and lack of input validation further exacerbate these risks. Caution is advised when using this code.

Live on npm for 42 minutes before removal. Socket users were protected even while the package was live.

azure-graphrbac

7.2.4

Removed from npm

Blocked by Socket

The code exhibits clear signs of malicious behavior by exfiltrating system and project data to external servers. The lack of obfuscation does not mitigate the severity of the threat. The high malware and risk scores reflect the serious nature of these activities.

Live on npm for 1 hour and 34 minutes before removal. Socket users were protected even while the package was live.

wallet-watch-asset

1.0.2

by syt4sh1

Removed from npm

Blocked by Socket

This code snippet is likely malicious. It is designed to extract sensitive system and process data and send them over the network to a certain target URL. It also has the potential to execute shell commands. These behaviors suggest a potential backdoor or information stealing malware.

Live on npm for 9 days, 10 hours and 15 minutes before removal. Socket users were protected even while the package was live.

azure-graphrbac

2.0.5

Removed from npm

Blocked by Socket

The code exhibits clear malicious behavior by sending sensitive system data over the network and potentially exfiltrating project details. The presence of an infinite loop and repeated network requests to suspicious domains further indicates a high risk of data theft and privacy violations.

Live on npm for 36 minutes before removal. Socket users were protected even while the package was live.

fiji-core-foc

3.999.0

by officeathand

Removed from npm

Blocked by Socket

The code is highly likely to be malicious due to its suspicious behavior of gathering sensitive system information and sending it to an external server. Its purpose appears to be system reconnaissance which is a common characteristic of malware. It's strongly advised not to use this code.

Live on npm for 21 days, 6 hours and 2 minutes before removal. Socket users were protected even while the package was live.

pattern-middleware

1.99.99

by biskitfaulty

Removed from npm

Blocked by Socket

The code sends sensitive data to an unauthorized or malicious domain using DNS queries, and poses a high security risk. It should be removed immediately from any project.

Live on npm for 3 minutes before removal. Socket users were protected even while the package was live.

esm-node-services

0.7.14

by ije

Removed from npm

Blocked by Socket

The code contains multiple sources of untrusted user input and utilizes them in ways that could lead to arbitrary code execution and security vulnerabilities. It lacks proper input validation and sanitization, making it susceptible to supply chain attacks and code injection. Therefore, it poses a high security risk.

Live on npm for 18 days, 16 hours and 33 minutes before removal. Socket users were protected even while the package was live.

rdkit

2022.9.2

Live on pypi

Blocked by Socket

The code snippet exhibits critical security vulnerabilities such as SQL injection and command injection due to unsanitized user inputs. Immediate action is required to implement input validation and sanitization to mitigate these risks.

hhland

1.2.0

by 17b4a931

Removed from npm

Blocked by Socket

This code poses a serious security risk and should not be used.

Live on npm for 4 minutes before removal. Socket users were protected even while the package was live.

aysa-web-core

5.9877.1

Removed from npm

Blocked by Socket

The script exhibits clear malicious behavior by sending sensitive system information to an external server without user consent. This poses a significant security risk due to potential data theft and system compromise.

Live on npm for 33 minutes before removal. Socket users were protected even while the package was live.

deahub

1.0.0

by semwangy

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

usaa-combobox

1.0.0

by brugninho

Removed from npm

Blocked by Socket

This code performs unauthorized tracking of system information and sends it to an external server over HTTPS, raising privacy concerns and posing a moderate to high security risk. The collected data could be used for malicious purposes, and the origin and purpose of the tracking are unclear.

Live on npm for 7 hours and 2 minutes before removal. Socket users were protected even while the package was live.

mcha

1.2.0

by 17b4a931

Removed from npm

Blocked by Socket

This code poses a serious security risk and should not be used.

Live on npm for 31 minutes before removal. Socket users were protected even while the package was live.

three-d-secure

4.8.2

by bugbounty-automation

Removed from npm

Blocked by Socket

The code is highly suspicious and exhibits behavior consistent with malware. It collects extensive system information and sends it to external servers without user consent, using both HTTPS and DNS queries. The methods used for data transmission are covert, indicating a high risk of data exfiltration and privacy invasion.

Live on npm for 28 minutes before removal. Socket users were protected even while the package was live.

nodejs-socket

11.2.1

by signup0001

Removed from npm

Blocked by Socket

This package was removed from the npm registry for security reasons.

Detect and block software supply chain attacks

Socket detects traditional vulnerabilities (CVEs) but goes beyond that to scan the actual code of dependencies for malicious behavior. It proactively detects and blocks 70+ signals of supply chain risk in open source code, for comprehensive protection.

Possible typosquat attack

Known malware

AI-detected potential malware

Suspicious Stars on GitHub

GitHub dependency

Git dependency

Obfuscated code

NPM Shrinkwrap

Telemetry

Protestware or potentially unwanted behavior

19 more alerts

Detect suspicious package updates in real-time

Socket detects and blocks malicious dependencies, often within just minutes of them being published to public registries, making it the most effective tool for blocking zero-day supply chain attacks.

GitHub app screenshot

Developers love Socket

Socket is built by a team of prolific open source maintainers whose software is downloaded over 1 billion times per month. We understand how to build tools that developers love. But don’t take our word for it.

Even more developer love

Security teams trust Socket

The best security teams in the world use Socket to get visibility into supply chain risk, and to build a security feedback loop into the development process.

Even more security team love
Book a DemoLearn more

Why teams choose Socket

Pro-active security

Depend on Socket to prevent malicious open source dependencies from infiltrating your app.

Easy to install

Install the Socket GitHub App in just 2 clicks and get protected today.

Comprehensive open source protection

Block 70+ issues in open source code, including malware, typo-squatting, hidden code, misleading packages, permission creep, and more.

Develop faster

Reduce work by surfacing actionable security information directly in GitHub. Empower developers to make better decisions.

Supply chain attacks are on the rise

Attackers have taken notice of the opportunity to attack organizations through open source dependencies. Supply chain attacks rose a whopping 700% in the past year, with over 15,000 recorded attacks.

Dec 14, 2023

Hijacked cryptocurrency library adds malware

Widely-used library in cryptocurrency frontend was compromised to include wallet-draining code, following the hijacking of NPM account credentials via phishing.

Jan 06, 2022

Maintainer intentionally adds malware

Rogue maintainer sabotages his own open source package with 100M downloads/month, notably breaking Amazon's AWS SDK.

Nov 15, 2021

npm discovers a platform vulnerability allowing unauthorized publishing of any package

Attackers could publish new versions of any npm package without authorization for multiple years.

Oct 22, 2021

Hijacked package adds cryptominers and password-stealing malware

Multiple packages with 30M downloads/month are hijacked and publish malicious versions directly into the software supply chain.

Nov 26, 2018

Package hijacked adding organization specific backdoors

Obfuscated malware added to a dependency which targeted a single company, went undetected for over a week, and made it into their production build.

Ready to dive in?

Get protected by Socket with just 2 clicks.

Install GitHub AppBook a Demo

The latest from the Socket team

Get our latest security research, open source insights, and product updates.

View all articles
SocketSocket SOC 2 Logo

Product

Packages

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc