

Socket
2.7K posts

@SocketSecurity
Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. 👀 @npm_malware



🛑 ALERT - Trivy, a popular open-source vulnerability scanner, was compromised after attackers hijacked 75 version tags in #GitHub Actions to deliver an infostealer. It ran in CI pipelines, stealing creds and tokens, then exfiltrating data or staging it via stolen GitHub PATs. 🔗 Attack flow, impacted versions, fixes → thehackernews.com/2026/03/trivy-…













🚨 Trivy is under attack again. Attackers force-pushed 75 of 76 tags in aquasecurity/trivy-action, impacting 10K+ workflows and turning trusted GitHub Actions into malware. Any version ≠ v0.35.0 may execute an infostealer in CI. Analysis forthcoming: socket.dev/blog/trivy-und…

🚨 GlassWorm sleeper extensions are now activating on Open VSX. - 20+ new malicious extensions and ~20 sleepers. - Some later weaponized to deliver malware via extension updates. Latest shift: GitHub-hosted VSIX payloads bypass registry takedowns. socket.dev/blog/glassworm…




🚨 New Research: We found 73 malicious Open VSX extensions tied to the GlassWorm campaign. Attackers are now spreading the malware transitively by abusing VS Code extension packs and dependencies. Details → socket.dev/blog/open-vsx-… #openvsx #vscode
