Secure OSS Dependencies
Beyond CVE Scanning
Open source code makes up more than 90% of modern software projects, with many apps spamming 10,000+ dependencies. This makes it easy for attackers to use open source as a vector for attacks where open source packages registries are frequently the target of malware. Traditional vulnerability scanners cannot detect active supply chain attacks. Socket's free GitHub app safeguards your open source code from both vulnerable and malicious dependencies.
carousel-zinnia-eki119
1.0.0
by afifaljafari112
Removed from npm
Blocked by Socket
The code heavily relies on multiple external dependencies with unconventional names and invokes unspecified methods without any validation or error handling. This raises concerns about potential malicious behavior, especially given the lack of documentation and clarity. While the code itself does not show explicit malicious actions, the use of these dependencies without verification is risky.
Live on npm for 57 days, 2 hours and 16 minutes before removal. Socket users were protected even while the package was live.
pet-master-tours-gratuits-pour-coins-et-spins-liens-quotidiens-489
1.0.2
by muhammadharunmiya44
Removed from npm
Blocked by Socket
The script seems to be part of a spamming operation and uses bad security practices, such as hardcoding paths and credentials. Therefore, it's a potential security risk.
Live on npm for 5 minutes before removal. Socket users were protected even while the package was live.
@zitterorg/laudantium-rerum
2.2.24
by loandinhb931
Live on npm
Blocked by Socket
Malicious code in @zitterorg/laudantium-rerum (npm) Source: ghsa-malware (e45ff91dd83cc149d7abc8c6fb2c74e3509aa341e23c72cfac0a34868a4e2637) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
akshansh-jaiswal-ctf
99.99.99
by ashleykutcher
Removed from npm
Blocked by Socket
This package was removed from the npm registry for security reasons.
extrafee
99.0.0
by lykos_poc1
Removed from npm
Blocked by Socket
The script is designed to collect and send sensitive information to an external server, which poses a significant security risk and is indicative of malicious behavior.
Live on npm for 4 hours and 31 minutes before removal. Socket users were protected even while the package was live.
fca-amir-remake
10.0.1
by farebiiw-amir
Removed from npm
Blocked by Socket
The code exhibits risky behavior by automatically installing packages from external sources without user confirmation, using hardcoded URLs and package names, and logging potentially sensitive information. The risk of unauthorized package installations and arbitrary code execution is high. While there are no direct signs of malicious intent, caution is advised when using this code.
Live on npm for 57 minutes before removal. Socket users were protected even while the package was live.
@swenkerorg/nulla-voluptates-voluptates
1.0.0
by swenkertreanpm
Removed from npm
Blocked by Socket
This package was removed from the npm registry for security reasons.
Live on npm for 14 minutes before removal. Socket users were protected even while the package was live.
whistle-bamboo-awy674
1.0.0
by afifaljafari112
Removed from npm
Blocked by Socket
The provided code imports multiple modules and calls a function 'functame' on each. The use of unconventional naming patterns for variables and functions, along with the lack of clarity about the purpose of the modules being imported, raises suspicion. However, without more information about what these modules do, it is difficult to definitively determine if the code contains malicious behavior.
Live on npm for 56 days, 15 hours and 52 minutes before removal. Socket users were protected even while the package was live.
ucs-data-table
2.99.99
Removed from npm
Blocked by Socket
The code uses the exec function to run shell commands, which poses a significant security risk. It could potentially execute malicious code if the input to exec is manipulated. Redirecting output to /dev/null to hide execution details is suspicious.
Live on npm for 34 minutes before removal. Socket users were protected even while the package was live.
gapuler
503.38.27
Removed from npm
Blocked by Socket
This package was removed from the npm registry for security reasons.
Live on npm for 30 minutes before removal. Socket users were protected even while the package was live.
feature-flag-framework
0.999.0
by officeathand
Removed from npm
Blocked by Socket
This script is malicious as it gathers sensitive system information and sends it to a remote server without the user's knowledge or consent.
Live on npm for 18 days, 20 hours and 51 minutes before removal. Socket users were protected even while the package was live.
djs-sb-v13
1.0.0
by discord-selfbots
Removed from npm
Blocked by Socket
The code exhibits clear signs of malicious behavior, specifically token and potential credential exfiltration to an external server. The presence of hardcoded URLs to post user tokens and the use of eval() function are definitive indicators of malicious intent.
Live on npm for 10 days, 4 hours and 6 minutes before removal. Socket users were protected even while the package was live.
stealerdiscord
1.4
Live on pypi
Blocked by Socket
The code exhibits several indicators of malicious behavior, including process termination, unauthorized modification of application files, and potential data exfiltration via webhooks. The use of obfuscated code further suggests malicious intent.
fern-vortex-yzn169-project
1.0.0
by afifcapcut112
Removed from npm
Blocked by Socket
The code appears suspicious due to the invalid syntax involving hyphens in variable/module names and the uniform 'functame' function calls. However, without the actual implementation of the required modules, it is difficult to conclusively determine if the code is malicious. Further inspection of the mentioned modules is required.
Live on npm for 57 days, 6 hours and 3 minutes before removal. Socket users were protected even while the package was live.
com.unity.ide.vscode
5.0.5
Removed from npm
Blocked by Socket
The script collects information like package name, directory path, home directory, hostname, username, DNS servers, package version, and package.json content, and sends it to a remote server.
Live on npm for 3 minutes before removal. Socket users were protected even while the package was live.
@taktikorg/quo-autem
1.0.0
by lechuongb878
Removed from npm
Blocked by Socket
This package was removed from the npm registry for security reasons.
Live on npm for 1 hour before removal. Socket users were protected even while the package was live.
@zitterorg/laudantium-rerum
2.1.7
by loandinhb931
Live on npm
Blocked by Socket
Malicious code in @zitterorg/laudantium-rerum (npm) Source: ghsa-malware (e45ff91dd83cc149d7abc8c6fb2c74e3509aa341e23c72cfac0a34868a4e2637) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
cbdev2024test
5.0.0
by cbdev2024
Removed from npm
Blocked by Socket
The package 'cbdev2024test' version '5.0.0' contains a 'preinstall' script that executes 'curl' commands to external endpoints during installation. Specifically, it sends HTTP requests to: - `https://webhook[.]site/199553c3-ea00-411d-9d8e-b119b0ebefd5/start` - `hxxps://34.165.144.112:25632/` - `https://webhook[.]site/199553c3-ea00-411d-9d8e-b119b0ebefd5/end` This behavior can be used to collect system information, perform unauthorized network communication, or download malicious content, posing a significant security risk to users.
Live on npm for 1 hour and 15 minutes before removal. Socket users were protected even while the package was live.
chat-web-sdk
9.9.9
by coverallsjab
Removed from npm
Blocked by Socket
The code sends sensitive data to an unauthorized or malicious domain using DNS queries, and poses a high security risk. It should be removed immediately from any project.
Live on npm for 6 minutes before removal. Socket users were protected even while the package was live.
@zitterorg/laudantium-rerum
2.2.21
by loandinhb931
Live on npm
Blocked by Socket
Malicious code in @zitterorg/laudantium-rerum (npm) Source: ghsa-malware (e45ff91dd83cc149d7abc8c6fb2c74e3509aa341e23c72cfac0a34868a4e2637) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
danafonts
0.999.999
Removed from npm
Blocked by Socket
The script is making a HTTP request to an external URL. This behavior could potentially be used for data exfiltration or to download malicious payloads. It poses a security risk and should be investigated further.
Live on npm for 30 minutes before removal. Socket users were protected even while the package was live.
editor-elements
4.999.999
Removed from npm
Blocked by Socket
The code uses the exec function to run shell commands, which poses a significant security risk. It could potentially execute malicious code if the input to exec is manipulated. Redirecting output to /dev/null to hide execution details is suspicious.
Live on npm for 1 hour and 12 minutes before removal. Socket users were protected even while the package was live.
yandex-yt-proto
103.99.99
by ypvpctpbamdhxtkzdu
Removed from npm
Blocked by Socket
The script collects detailed system information and sends it to a remote server, which is a significant privacy violation and potentially malicious behavior. This data collection and transmission could be used for unauthorized access or further exploitation.
Live on npm for 18 minutes before removal. Socket users were protected even while the package was live.
deploy-pages
4.3.0
by snapkit
Live on npm
Blocked by Socket
The script is designed to send sensitive information from the system to an external server, indicating malicious intent and a high security risk.
conversations-prop-types
3.999.999
Removed from npm
Blocked by Socket
The code uses the exec function to run shell commands, which poses a significant security risk. It could potentially execute malicious code if the input to exec is manipulated. Redirecting output to /dev/null to hide execution details is suspicious.
Live on npm for 59 minutes before removal. Socket users were protected even while the package was live.
carousel-zinnia-eki119
1.0.0
by afifaljafari112
Removed from npm
Blocked by Socket
The code heavily relies on multiple external dependencies with unconventional names and invokes unspecified methods without any validation or error handling. This raises concerns about potential malicious behavior, especially given the lack of documentation and clarity. While the code itself does not show explicit malicious actions, the use of these dependencies without verification is risky.
Live on npm for 57 days, 2 hours and 16 minutes before removal. Socket users were protected even while the package was live.
pet-master-tours-gratuits-pour-coins-et-spins-liens-quotidiens-489
1.0.2
by muhammadharunmiya44
Removed from npm
Blocked by Socket
The script seems to be part of a spamming operation and uses bad security practices, such as hardcoding paths and credentials. Therefore, it's a potential security risk.
Live on npm for 5 minutes before removal. Socket users were protected even while the package was live.
@zitterorg/laudantium-rerum
2.2.24
by loandinhb931
Live on npm
Blocked by Socket
Malicious code in @zitterorg/laudantium-rerum (npm) Source: ghsa-malware (e45ff91dd83cc149d7abc8c6fb2c74e3509aa341e23c72cfac0a34868a4e2637) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
akshansh-jaiswal-ctf
99.99.99
by ashleykutcher
Removed from npm
Blocked by Socket
This package was removed from the npm registry for security reasons.
extrafee
99.0.0
by lykos_poc1
Removed from npm
Blocked by Socket
The script is designed to collect and send sensitive information to an external server, which poses a significant security risk and is indicative of malicious behavior.
Live on npm for 4 hours and 31 minutes before removal. Socket users were protected even while the package was live.
fca-amir-remake
10.0.1
by farebiiw-amir
Removed from npm
Blocked by Socket
The code exhibits risky behavior by automatically installing packages from external sources without user confirmation, using hardcoded URLs and package names, and logging potentially sensitive information. The risk of unauthorized package installations and arbitrary code execution is high. While there are no direct signs of malicious intent, caution is advised when using this code.
Live on npm for 57 minutes before removal. Socket users were protected even while the package was live.
@swenkerorg/nulla-voluptates-voluptates
1.0.0
by swenkertreanpm
Removed from npm
Blocked by Socket
This package was removed from the npm registry for security reasons.
Live on npm for 14 minutes before removal. Socket users were protected even while the package was live.
whistle-bamboo-awy674
1.0.0
by afifaljafari112
Removed from npm
Blocked by Socket
The provided code imports multiple modules and calls a function 'functame' on each. The use of unconventional naming patterns for variables and functions, along with the lack of clarity about the purpose of the modules being imported, raises suspicion. However, without more information about what these modules do, it is difficult to definitively determine if the code contains malicious behavior.
Live on npm for 56 days, 15 hours and 52 minutes before removal. Socket users were protected even while the package was live.
ucs-data-table
2.99.99
Removed from npm
Blocked by Socket
The code uses the exec function to run shell commands, which poses a significant security risk. It could potentially execute malicious code if the input to exec is manipulated. Redirecting output to /dev/null to hide execution details is suspicious.
Live on npm for 34 minutes before removal. Socket users were protected even while the package was live.
gapuler
503.38.27
Removed from npm
Blocked by Socket
This package was removed from the npm registry for security reasons.
Live on npm for 30 minutes before removal. Socket users were protected even while the package was live.
feature-flag-framework
0.999.0
by officeathand
Removed from npm
Blocked by Socket
This script is malicious as it gathers sensitive system information and sends it to a remote server without the user's knowledge or consent.
Live on npm for 18 days, 20 hours and 51 minutes before removal. Socket users were protected even while the package was live.
djs-sb-v13
1.0.0
by discord-selfbots
Removed from npm
Blocked by Socket
The code exhibits clear signs of malicious behavior, specifically token and potential credential exfiltration to an external server. The presence of hardcoded URLs to post user tokens and the use of eval() function are definitive indicators of malicious intent.
Live on npm for 10 days, 4 hours and 6 minutes before removal. Socket users were protected even while the package was live.
stealerdiscord
1.4
Live on pypi
Blocked by Socket
The code exhibits several indicators of malicious behavior, including process termination, unauthorized modification of application files, and potential data exfiltration via webhooks. The use of obfuscated code further suggests malicious intent.
fern-vortex-yzn169-project
1.0.0
by afifcapcut112
Removed from npm
Blocked by Socket
The code appears suspicious due to the invalid syntax involving hyphens in variable/module names and the uniform 'functame' function calls. However, without the actual implementation of the required modules, it is difficult to conclusively determine if the code is malicious. Further inspection of the mentioned modules is required.
Live on npm for 57 days, 6 hours and 3 minutes before removal. Socket users were protected even while the package was live.
com.unity.ide.vscode
5.0.5
Removed from npm
Blocked by Socket
The script collects information like package name, directory path, home directory, hostname, username, DNS servers, package version, and package.json content, and sends it to a remote server.
Live on npm for 3 minutes before removal. Socket users were protected even while the package was live.
@taktikorg/quo-autem
1.0.0
by lechuongb878
Removed from npm
Blocked by Socket
This package was removed from the npm registry for security reasons.
Live on npm for 1 hour before removal. Socket users were protected even while the package was live.
@zitterorg/laudantium-rerum
2.1.7
by loandinhb931
Live on npm
Blocked by Socket
Malicious code in @zitterorg/laudantium-rerum (npm) Source: ghsa-malware (e45ff91dd83cc149d7abc8c6fb2c74e3509aa341e23c72cfac0a34868a4e2637) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
cbdev2024test
5.0.0
by cbdev2024
Removed from npm
Blocked by Socket
The package 'cbdev2024test' version '5.0.0' contains a 'preinstall' script that executes 'curl' commands to external endpoints during installation. Specifically, it sends HTTP requests to: - `https://webhook[.]site/199553c3-ea00-411d-9d8e-b119b0ebefd5/start` - `hxxps://34.165.144.112:25632/` - `https://webhook[.]site/199553c3-ea00-411d-9d8e-b119b0ebefd5/end` This behavior can be used to collect system information, perform unauthorized network communication, or download malicious content, posing a significant security risk to users.
Live on npm for 1 hour and 15 minutes before removal. Socket users were protected even while the package was live.
chat-web-sdk
9.9.9
by coverallsjab
Removed from npm
Blocked by Socket
The code sends sensitive data to an unauthorized or malicious domain using DNS queries, and poses a high security risk. It should be removed immediately from any project.
Live on npm for 6 minutes before removal. Socket users were protected even while the package was live.
@zitterorg/laudantium-rerum
2.2.21
by loandinhb931
Live on npm
Blocked by Socket
Malicious code in @zitterorg/laudantium-rerum (npm) Source: ghsa-malware (e45ff91dd83cc149d7abc8c6fb2c74e3509aa341e23c72cfac0a34868a4e2637) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
danafonts
0.999.999
Removed from npm
Blocked by Socket
The script is making a HTTP request to an external URL. This behavior could potentially be used for data exfiltration or to download malicious payloads. It poses a security risk and should be investigated further.
Live on npm for 30 minutes before removal. Socket users were protected even while the package was live.
editor-elements
4.999.999
Removed from npm
Blocked by Socket
The code uses the exec function to run shell commands, which poses a significant security risk. It could potentially execute malicious code if the input to exec is manipulated. Redirecting output to /dev/null to hide execution details is suspicious.
Live on npm for 1 hour and 12 minutes before removal. Socket users were protected even while the package was live.
yandex-yt-proto
103.99.99
by ypvpctpbamdhxtkzdu
Removed from npm
Blocked by Socket
The script collects detailed system information and sends it to a remote server, which is a significant privacy violation and potentially malicious behavior. This data collection and transmission could be used for unauthorized access or further exploitation.
Live on npm for 18 minutes before removal. Socket users were protected even while the package was live.
deploy-pages
4.3.0
by snapkit
Live on npm
Blocked by Socket
The script is designed to send sensitive information from the system to an external server, indicating malicious intent and a high security risk.
conversations-prop-types
3.999.999
Removed from npm
Blocked by Socket
The code uses the exec function to run shell commands, which poses a significant security risk. It could potentially execute malicious code if the input to exec is manipulated. Redirecting output to /dev/null to hide execution details is suspicious.
Live on npm for 59 minutes before removal. Socket users were protected even while the package was live.
Proactively search and detect dependencies across repositories in your organization, with actionable insights for your projects and SBOMs
Block emerging malware threats, including intentionally maintainer-added updates, along with packages that differ in name by only a few characters..
Get alerted when a dependency update introduces new risky API usage - filesystem, network, child_process, eval().
Detect obfuscated, minified, or hidden code.
Socket detects the sudden inclusion of a new maintainer, updates with telemetry or protestware added, dependencies pulled in from a remote git URL, and much more.
We help security teams work more efficiently
Get actionable alerts for the supply chain risks that matter. Socket highlights risky dependencies directly within the developer workflow.