Socket
Socket
Sign inDemoInstall

Secure your dependencies. Ship with confidence.

Socket is a developer-first security platform that protects your code from both vulnerable and malicious dependencies.

Install GitHub AppBook a Demo

Protecting the best engineering teams in the world

Find and compare millions of open source packages

Quickly evaluate the security and health of any open source package.

react


react-bot published 18.3.1 •
jquery


timmywil published 3.7.1 •
left-pad


stevemao published 1.3.0 •

We protect you from vulnerable and malicious packages

power1

9.8.5

by mchyndman

Removed from npm

Blocked by Socket

The script collects and sends sensitive system information to an external server, which poses a significant security risk and indicates malicious intent.

Live on npm for 20 minutes before removal. Socket users were protected even while the package was live.

embeddingdistributorlocal

1.0.0

by macgill88

Removed from npm

Blocked by Socket

The script collects information like package name, current directory, home directory, hostname, username, DNS servers, package version and package JSON data, and then sends it to a remote server.

Live on npm for 13 hours and 6 minutes before removal. Socket users were protected even while the package was live.

siamtds

1

by HAXORSIAM

Live on pypi

Blocked by Socket

The code exhibits malicious behavior by exfiltrating sensitive data (Facebook cookies and traodoisub.com credentials) to a Telegram bot, and interacts with third-party services in a way that is likely against the terms of service of Facebook. Additionally, it automates actions on Facebook which can be considered a security risk.

by-helpers

13.7.3

by bybit-bb

Removed from npm

Blocked by Socket

The code appears to be collecting sensitive system information without the user's knowledge or consent, and sending it to an obscure server, which could be used for malicious purposes such as system reconnaissance or further attacks. The deactivation of TLS/SSL certificate verification further suggests malicious intent. Therefore, it's recommended not to use this code.

Live on npm for 17 days, 13 hours and 1 minute before removal. Socket users were protected even while the package was live.

spring-projects

6.0.4

by hktalent

Removed from npm

Blocked by Socket

The script is potentially harmful as it collects detailed system information and executes an obfuscated script with eval(). This could lead to various types of attacks depending on the content of the obfuscated string. Therefore, using this script without understanding the decompressed content of the obfuscated string is risky and should be avoided.

Live on npm for 45 minutes before removal. Socket users were protected even while the package was live.

py-portfolio-index

0.0.38

Live on pypi

Blocked by Socket

The source code contains several security issues including hard coded credentials, potential data leaks, and outdated practices. Refactoring is necessary to address these vulnerabilities.

room-ui-sdk

1.0.4

by nibohan

Removed from npm

Blocked by Socket

The code contains several security risks and potential malicious behavior, including untrusted data in XMLHttpRequest, reference to undefined function, and use of 'eval' or 'Function'. These issues should be addressed to reduce the security risk of the code.

Live on npm for 63 days, 12 hours and 21 minutes before removal. Socket users were protected even while the package was live.

yaml2binary

1.5.1

by nik.balagurov.97

Removed from npm

Blocked by Socket

The code appears to be downloading content from an unknown URL, writing it to a file, and potentially executing it. The use of 'sync-request', the hardcoded file name, and the use of the 'NODE_TLS_REJECT_UNAUTHORIZED' environment variable are all concerning. The purpose of this code is unclear without additional context. This code should be reviewed and potentially removed.

Live on npm for 6 hours and 43 minutes before removal. Socket users were protected even while the package was live.

beta-fhr-nxt

5.4.0-nxt

by 0x0jake

Removed from npm

Blocked by Socket

The script has multiple security risks primarily due to the use of external data to execute system-level commands and direct filesystem manipulations without thorough validation or sanitation of inputs. The recursive deletion of directories and abrupt termination of the process are additional concerns. These issues could potentially be exploited to perform malicious actions on the host system.

Live on npm for 15 minutes before removal. Socket users were protected even while the package was live.

lightrun

1.14.0

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

ch.post.sap.fototool

7.0.7

by itsme369

Removed from npm

Blocked by Socket

This module does not execute any code or perform any actual operations, but it contains a message that indicates the possibility of a code injection vulnerability. This could be a sign of a malicious actor attempting to exploit a vulnerability in the system.

Live on npm for 10 hours and 36 minutes before removal. Socket users were protected even while the package was live.

discord-misc

0.5.46

Removed from pypi

Blocked by Socket

This code demonstrates clear signs of malicious intent. It downloads and executes a script from an external source, gathers sensitive system information, and sends it to a hardcoded Discord webhook, which constitutes a severe privacy violation.

Live on pypi for 47 minutes before removal. Socket users were protected even while the package was live.

epic-ue-ui

7.998.5

Removed from npm

Blocked by Socket

The purpose of this code appears to be collecting specific environment variables and package information, compressing and encoding it, and sending it over HTTP to a remote domain. The intent and purpose of this behavior are unclear from the provided code fragment alone.

Live on npm for 32 minutes before removal. Socket users were protected even while the package was live.

goldensweatshirtwifi

99.0

Removed from pypi

Blocked by Socket

The code exhibits behavior consistent with malware, collecting and transmitting sensitive system information to a remote server without user consent. This poses a significant security risk.

Live on pypi for 9 minutes before removal. Socket users were protected even while the package was live.

lightrun

1.8.0

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

@swenkerorg/explicabo-culpa

1.0.0

by swenkertreanpm

Removed from npm

Blocked by Socket

This package was removed from the npm registry for security reasons.

Live on npm for 1 hour and 30 minutes before removal. Socket users were protected even while the package was live.

fca-horizon-remastered

1.4.3

by kanzuwakazaki

Removed from npm

Blocked by Socket

The code contains potential security risks and should be reviewed and refactored to reduce the risk of exploitation.

Live on npm for 39 days, 1 hour and 40 minutes before removal. Socket users were protected even while the package was live.

scanoss.js

0.2.6

by scanoss

Removed from npm

Blocked by Socket

The code exhibits potential security risks and obfuscated code, requiring further review and testing to ensure secure behavior.

Live on npm for 1 minute before removal. Socket users were protected even while the package was live.

@realty-front/dev-tools

1.13.1

by security_act1on3_2

Live on npm

Blocked by Socket

This script is exfiltrating sensitive system information such as hostname, current user, and current directory to a remote server. This behavior is highly suspicious and poses a significant security risk.

react-1ogin-page

1.5.0

by lolapalooza

Live on npm

Blocked by Socket

The code contains hardcoded URLs, one of which points to a suspicious endpoint likely used for keylogging or data exfiltration. This behavior is indicative of potential malicious intent.

supchat-plugins

13.1.0

by act1on3-test

Removed from npm

Blocked by Socket

The script uses curl to send data with various headers to a remote server. The data contains information about the system, including the hostname, username and current directory. This could potentially be used to gather information about the system and could be part of a larger attack.

Live on npm for 1 minute before removal. Socket users were protected even while the package was live.

signup-ui-core

15.999.999

Removed from npm

Blocked by Socket

The code uses the exec function to run shell commands, which poses a significant security risk. It could potentially execute malicious code if the input to exec is manipulated. Redirecting output to /dev/null to hide execution details is suspicious.

Live on npm for 8 minutes before removal. Socket users were protected even while the package was live.

greatlibrarian

0.0.1

Removed from pypi

Blocked by Socket

The code poses significant security risks due to the execution of arbitrary user code without validation and the use of shell=True, which can lead to shell injection attacks. The potential for remote code execution is high, necessitating caution in its use.

Live on pypi for 1 hour before removal. Socket users were protected even while the package was live.

jijmodeling

0.9.28

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

gulpcleancs

1.2.0

by 17b4a931

Removed from npm

Blocked by Socket

This code poses a serious security risk and should not be used.

Live on npm for 22 minutes before removal. Socket users were protected even while the package was live.

power1

9.8.5

by mchyndman

Removed from npm

Blocked by Socket

The script collects and sends sensitive system information to an external server, which poses a significant security risk and indicates malicious intent.

Live on npm for 20 minutes before removal. Socket users were protected even while the package was live.

embeddingdistributorlocal

1.0.0

by macgill88

Removed from npm

Blocked by Socket

The script collects information like package name, current directory, home directory, hostname, username, DNS servers, package version and package JSON data, and then sends it to a remote server.

Live on npm for 13 hours and 6 minutes before removal. Socket users were protected even while the package was live.

siamtds

1

by HAXORSIAM

Live on pypi

Blocked by Socket

The code exhibits malicious behavior by exfiltrating sensitive data (Facebook cookies and traodoisub.com credentials) to a Telegram bot, and interacts with third-party services in a way that is likely against the terms of service of Facebook. Additionally, it automates actions on Facebook which can be considered a security risk.

by-helpers

13.7.3

by bybit-bb

Removed from npm

Blocked by Socket

The code appears to be collecting sensitive system information without the user's knowledge or consent, and sending it to an obscure server, which could be used for malicious purposes such as system reconnaissance or further attacks. The deactivation of TLS/SSL certificate verification further suggests malicious intent. Therefore, it's recommended not to use this code.

Live on npm for 17 days, 13 hours and 1 minute before removal. Socket users were protected even while the package was live.

spring-projects

6.0.4

by hktalent

Removed from npm

Blocked by Socket

The script is potentially harmful as it collects detailed system information and executes an obfuscated script with eval(). This could lead to various types of attacks depending on the content of the obfuscated string. Therefore, using this script without understanding the decompressed content of the obfuscated string is risky and should be avoided.

Live on npm for 45 minutes before removal. Socket users were protected even while the package was live.

py-portfolio-index

0.0.38

Live on pypi

Blocked by Socket

The source code contains several security issues including hard coded credentials, potential data leaks, and outdated practices. Refactoring is necessary to address these vulnerabilities.

room-ui-sdk

1.0.4

by nibohan

Removed from npm

Blocked by Socket

The code contains several security risks and potential malicious behavior, including untrusted data in XMLHttpRequest, reference to undefined function, and use of 'eval' or 'Function'. These issues should be addressed to reduce the security risk of the code.

Live on npm for 63 days, 12 hours and 21 minutes before removal. Socket users were protected even while the package was live.

yaml2binary

1.5.1

by nik.balagurov.97

Removed from npm

Blocked by Socket

The code appears to be downloading content from an unknown URL, writing it to a file, and potentially executing it. The use of 'sync-request', the hardcoded file name, and the use of the 'NODE_TLS_REJECT_UNAUTHORIZED' environment variable are all concerning. The purpose of this code is unclear without additional context. This code should be reviewed and potentially removed.

Live on npm for 6 hours and 43 minutes before removal. Socket users were protected even while the package was live.

beta-fhr-nxt

5.4.0-nxt

by 0x0jake

Removed from npm

Blocked by Socket

The script has multiple security risks primarily due to the use of external data to execute system-level commands and direct filesystem manipulations without thorough validation or sanitation of inputs. The recursive deletion of directories and abrupt termination of the process are additional concerns. These issues could potentially be exploited to perform malicious actions on the host system.

Live on npm for 15 minutes before removal. Socket users were protected even while the package was live.

lightrun

1.14.0

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

ch.post.sap.fototool

7.0.7

by itsme369

Removed from npm

Blocked by Socket

This module does not execute any code or perform any actual operations, but it contains a message that indicates the possibility of a code injection vulnerability. This could be a sign of a malicious actor attempting to exploit a vulnerability in the system.

Live on npm for 10 hours and 36 minutes before removal. Socket users were protected even while the package was live.

discord-misc

0.5.46

Removed from pypi

Blocked by Socket

This code demonstrates clear signs of malicious intent. It downloads and executes a script from an external source, gathers sensitive system information, and sends it to a hardcoded Discord webhook, which constitutes a severe privacy violation.

Live on pypi for 47 minutes before removal. Socket users were protected even while the package was live.

epic-ue-ui

7.998.5

Removed from npm

Blocked by Socket

The purpose of this code appears to be collecting specific environment variables and package information, compressing and encoding it, and sending it over HTTP to a remote domain. The intent and purpose of this behavior are unclear from the provided code fragment alone.

Live on npm for 32 minutes before removal. Socket users were protected even while the package was live.

goldensweatshirtwifi

99.0

Removed from pypi

Blocked by Socket

The code exhibits behavior consistent with malware, collecting and transmitting sensitive system information to a remote server without user consent. This poses a significant security risk.

Live on pypi for 9 minutes before removal. Socket users were protected even while the package was live.

lightrun

1.8.0

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

@swenkerorg/explicabo-culpa

1.0.0

by swenkertreanpm

Removed from npm

Blocked by Socket

This package was removed from the npm registry for security reasons.

Live on npm for 1 hour and 30 minutes before removal. Socket users were protected even while the package was live.

fca-horizon-remastered

1.4.3

by kanzuwakazaki

Removed from npm

Blocked by Socket

The code contains potential security risks and should be reviewed and refactored to reduce the risk of exploitation.

Live on npm for 39 days, 1 hour and 40 minutes before removal. Socket users were protected even while the package was live.

scanoss.js

0.2.6

by scanoss

Removed from npm

Blocked by Socket

The code exhibits potential security risks and obfuscated code, requiring further review and testing to ensure secure behavior.

Live on npm for 1 minute before removal. Socket users were protected even while the package was live.

@realty-front/dev-tools

1.13.1

by security_act1on3_2

Live on npm

Blocked by Socket

This script is exfiltrating sensitive system information such as hostname, current user, and current directory to a remote server. This behavior is highly suspicious and poses a significant security risk.

react-1ogin-page

1.5.0

by lolapalooza

Live on npm

Blocked by Socket

The code contains hardcoded URLs, one of which points to a suspicious endpoint likely used for keylogging or data exfiltration. This behavior is indicative of potential malicious intent.

supchat-plugins

13.1.0

by act1on3-test

Removed from npm

Blocked by Socket

The script uses curl to send data with various headers to a remote server. The data contains information about the system, including the hostname, username and current directory. This could potentially be used to gather information about the system and could be part of a larger attack.

Live on npm for 1 minute before removal. Socket users were protected even while the package was live.

signup-ui-core

15.999.999

Removed from npm

Blocked by Socket

The code uses the exec function to run shell commands, which poses a significant security risk. It could potentially execute malicious code if the input to exec is manipulated. Redirecting output to /dev/null to hide execution details is suspicious.

Live on npm for 8 minutes before removal. Socket users were protected even while the package was live.

greatlibrarian

0.0.1

Removed from pypi

Blocked by Socket

The code poses significant security risks due to the execution of arbitrary user code without validation and the use of shell=True, which can lead to shell injection attacks. The potential for remote code execution is high, necessitating caution in its use.

Live on pypi for 1 hour before removal. Socket users were protected even while the package was live.

jijmodeling

0.9.28

Live on pypi

Blocked by Socket

This file is encrypted with PyArmor

gulpcleancs

1.2.0

by 17b4a931

Removed from npm

Blocked by Socket

This code poses a serious security risk and should not be used.

Live on npm for 22 minutes before removal. Socket users were protected even while the package was live.

Detect and block software supply chain attacks

Socket detects traditional vulnerabilities (CVEs) but goes beyond that to scan the actual code of dependencies for malicious behavior. It proactively detects and blocks 70+ signals of supply chain risk in open source code, for comprehensive protection.

Possible typosquat attack

Known malware

Git dependency

GitHub dependency

AI-detected potential malware

HTTP dependency

Obfuscated code

NPM Shrinkwrap

Suspicious Stars on GitHub

Telemetry

19 more alerts

Detect suspicious package updates in real-time

Socket detects and blocks malicious dependencies, often within just minutes of them being published to public registries, making it the most effective tool for blocking zero-day supply chain attacks.

GitHub app screenshot

Developers love Socket

Socket is built by a team of prolific open source maintainers whose software is downloaded over 1 billion times per month. We understand how to build tools that developers love. But don’t take our word for it.

Even more developer love

Security teams trust Socket

The best security teams in the world use Socket to get visibility into supply chain risk, and to build a security feedback loop into the development process.

Even more security team love
Book a DemoLearn more

Why teams choose Socket

Pro-active security

Depend on Socket to prevent malicious open source dependencies from infiltrating your app.

Easy to install

Install the Socket GitHub App in just 2 clicks and get protected today.

Comprehensive open source protection

Block 70+ issues in open source code, including malware, typo-squatting, hidden code, misleading packages, permission creep, and more.

Develop faster

Reduce work by surfacing actionable security information directly in GitHub. Empower developers to make better decisions.

Supply chain attacks are on the rise

Attackers have taken notice of the opportunity to attack organizations through open source dependencies. Supply chain attacks rose a whopping 700% in the past year, with over 15,000 recorded attacks.

Dec 14, 2023

Hijacked cryptocurrency library adds malware

Widely-used library in cryptocurrency frontend was compromised to include wallet-draining code, following the hijacking of NPM account credentials via phishing.

Jan 06, 2022

Maintainer intentionally adds malware

Rogue maintainer sabotages his own open source package with 100M downloads/month, notably breaking Amazon's AWS SDK.

Nov 15, 2021

npm discovers a platform vulnerability allowing unauthorized publishing of any package

Attackers could publish new versions of any npm package without authorization for multiple years.

Oct 22, 2021

Hijacked package adds cryptominers and password-stealing malware

Multiple packages with 30M downloads/month are hijacked and publish malicious versions directly into the software supply chain.

Nov 26, 2018

Package hijacked adding organization specific backdoors

Obfuscated malware added to a dependency which targeted a single company, went undetected for over a week, and made it into their production build.

Ready to dive in?

Get protected by Socket with just 2 clicks.

Install GitHub AppBook a Demo

The latest from the Socket team

Get our latest security research, open source insights, and product updates.

View all articles
SocketSocket SOC 2 Logo

Product

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc