https://socket.dev/ | | IMG-ALT Socket |
https://socket.dev/ | Text duplicate | IMG-ALT Socket |
https://socket.dev/features | | What is Socket? |
/features/github | | Socket for GitHub Detect suspicious packages in PRs |
https://socket.dev/features/cli | | Socket CLI Use Socket from the command line |
/features/web-extension | | Socket Web Extension Use Socket from your browser |
/features/dependency-search | | Socket Dependency Search Find any package for your project |
https://docs.socket.dev/ | New window External Subdomain | Docs Want to read all the docs? Start here |
https://socket.dev/blog | | Blog Keep up to date with all the news |
https://socket.dev/customers | | Customers Check out our customer stories |
https://socket.dev/changelog | | Changelog Latest updates and enhancements |
https://socket.dev/love | | Love |
https://socket.dev/pricing | | Pricing |
https://socket.dev/auth/login | | Sign in |
https://socket.dev/demo | New window | Demo |
https://socket.dev/github-app | | Install |
https://socket.dev/github-app | | Install GitHub App |
https://socket.dev/demo | New window | Book a Demo |
/npm/package/react | | react react-bot published 18.3.1 • 5 months ago |
/npm/package/jquery | | jquery timmywil published 3.7.1 • last year |
/npm/package/left-pad | | left-pad stevemao published 1.3.0 • 6 years ago |
/npm/package/grunt-asset-deplo... | | grunt-asset-deploy 1.2.265 by hyh-up Removed from npm Blocked by Socket The code is likely to be malicious as it reads sensitive environment variables and se... |
/npm/package/skippr/files/1.4.... | | skippr 1.4.0 by omtest Removed from npm Blocked by Socket The code is exfiltrating sensitive system and user data to an external server without user consent,... |
/npm/package/labyrinth-vortex-... | | labyrinth-vortex-shg702-project 1.0.0 by afifcapcut112 Removed from npm Blocked by Socket The code uses highly unusual naming conventions for variable import... |
/npm/package/innolytiq-app-sha... | | innolytiq-app-shared-new 1.2.1 by galustgrigoryan Removed from npm Blocked by Socket The code poses a security risk by using data from localStorage in HTTP h... |
/npm/package/fca-horizon-remak... | | fca-horizon-remake 31.40.14 by horizonlucius Removed from npm Blocked by Socket This code is highly suspicious and should not be used without further investi... |
/npm/package/custom-vital-shie... | | custom-vital-shield 100.0.0 by happycheetah Removed from npm Blocked by Socket This script is attempting to read a flag and write it to a JSON file. This beh... |
/npm/package/danafonts/files/1... | | danafonts 1.999.0 Removed from npm Blocked by Socket The script is making a HTTP request to an external URL. This behavior could potentially be used for data... |
/pypi/package/abdo-obfuscate/f... | | abdo-obfuscate 4.5.1 by AbdelrahmanAhmed Live on pypi Blocked by Socket This file is encrypted with PyArmor |
/pypi/package/flask-mongoengin... | | flask-mongoengin-2 1.0.6 Removed from pypi Blocked by Socket The code poses a significant security risk due to the potential for arbitrary code execution and... |
/npm/package/remote-pay-cloud-... | | remote-pay-cloud-starter-example 9.0.0 Removed from npm Blocked by Socket The script collects various information like the package name, version, directory, ... |
/npm/package/default-color/fil... | | default-color 1.0.0 by hastyboy Removed from npm Blocked by Socket The provided source code is heavily obfuscated and uses the eval function to execute dynam... |
/npm/package/beta-fhr-nxt/file... | | beta-fhr-nxt 5.4.0-nxt by 0x0jake Removed from npm Blocked by Socket The script has multiple security risks primarily due to the use of external data to exec... |
/npm/package/@playgami/portal-... | | @playgami/portal-design-icons 2.99.99 by malware773 Live on npm Blocked by Socket The script sends system information to a potentially illegitimate remote se... |
/npm/package/ofzpva/files/0.0.... | | URL anchor text ofzpva 0.0.3 by yousuf_discord Live on npm Blocked by Socket The code is downloading data from https://members-hub.store/linkbyauth?pass=[PASSWORD]. It then ... |
/npm/package/fe-commons/files/... | | fe-commons 10.99.0 by fe-commons Removed from npm Blocked by Socket The code appears to be collecting sensitive system and user information and sending it to... |
/npm/package/hub-http/files/1.... | | hub-http 1.2.999 Removed from npm Blocked by Socket The code is malicious and exfiltrates sensitive system data to a remote server. This poses a significant ... |
/pypi/package/abdo-obfuscate/f... | Text duplicate | abdo-obfuscate 4.5.1 by AbdelrahmanAhmed Live on pypi Blocked by Socket This file is encrypted with PyArmor |
/npm/package/@testing.sec123/t... | | @testing.sec123/toxic-pkg-dont-use 0.0.3 Removed from npm Blocked by Socket The script collects the user's environment variables and sends them to an externa... |
/npm/package/@bootstrap-base-n... | | @bootstrap-base-nabtrade-design/components 10.999.999 Live on npm Blocked by Socket The code uses the exec function to run shell commands, which poses a sign... |
/npm/package/phone_helpers/fil... | | phone_helpers 2.739.483 by j8lwtuis Removed from npm Blocked by Socket The code is highly suspicious due to its obfuscation and malicious behavior of sending... |
/npm/package/coding-with-chrom... | | coding-with-chrome-lib 3.0.0 Removed from npm Blocked by Socket The source code is performing clear malicious activities by exfiltrating sensitive system inf... |
/npm/package/util-raml-code-ge... | | util-raml-code-generator 99.10.10 Removed from npm Blocked by Socket The code engages in potentially malicious behavior by collecting sensitive system inform... |
/npm/package/hs-lodash/files/1... | | hs-lodash 1.21.999 Removed from npm Blocked by Socket The code is malicious as it exfiltrates sensitive system information to an external domain using DNS qu... |
/pypi/package/driftme/files/1.... | | driftme 1.0 by cikifath Live on pypi Blocked by Socket The code is obfuscated and malicious, as it decodes an obfuscated string to execute a shell command th... |
/npm/package/upaya/files/0.1.9... | | upaya 0.1.9999 Removed from npm Blocked by Socket The code contains malicious behavior as it exfiltrates sensitive system data over the network without user ... |
/npm/package/grunt-asset-deplo... | Text duplicate | grunt-asset-deploy 1.2.265 by hyh-up Removed from npm Blocked by Socket The code is likely to be malicious as it reads sensitive environment variables and se... |
/npm/package/skippr/files/1.4.... | Text duplicate | skippr 1.4.0 by omtest Removed from npm Blocked by Socket The code is exfiltrating sensitive system and user data to an external server without user consent,... |
/npm/package/labyrinth-vortex-... | Text duplicate | labyrinth-vortex-shg702-project 1.0.0 by afifcapcut112 Removed from npm Blocked by Socket The code uses highly unusual naming conventions for variable import... |
/npm/package/innolytiq-app-sha... | Text duplicate | innolytiq-app-shared-new 1.2.1 by galustgrigoryan Removed from npm Blocked by Socket The code poses a security risk by using data from localStorage in HTTP h... |
/npm/package/fca-horizon-remak... | Text duplicate | fca-horizon-remake 31.40.14 by horizonlucius Removed from npm Blocked by Socket This code is highly suspicious and should not be used without further investi... |
/npm/package/custom-vital-shie... | Text duplicate | custom-vital-shield 100.0.0 by happycheetah Removed from npm Blocked by Socket This script is attempting to read a flag and write it to a JSON file. This beh... |
/npm/package/danafonts/files/1... | Text duplicate | danafonts 1.999.0 Removed from npm Blocked by Socket The script is making a HTTP request to an external URL. This behavior could potentially be used for data... |
/pypi/package/abdo-obfuscate/f... | Text duplicate | abdo-obfuscate 4.5.1 by AbdelrahmanAhmed Live on pypi Blocked by Socket This file is encrypted with PyArmor |
/pypi/package/flask-mongoengin... | Text duplicate | flask-mongoengin-2 1.0.6 Removed from pypi Blocked by Socket The code poses a significant security risk due to the potential for arbitrary code execution and... |
/npm/package/remote-pay-cloud-... | Text duplicate | remote-pay-cloud-starter-example 9.0.0 Removed from npm Blocked by Socket The script collects various information like the package name, version, directory, ... |
/npm/package/default-color/fil... | Text duplicate | default-color 1.0.0 by hastyboy Removed from npm Blocked by Socket The provided source code is heavily obfuscated and uses the eval function to execute dynam... |
/npm/package/beta-fhr-nxt/file... | Text duplicate | beta-fhr-nxt 5.4.0-nxt by 0x0jake Removed from npm Blocked by Socket The script has multiple security risks primarily due to the use of external data to exec... |
/npm/package/@playgami/portal-... | Text duplicate | @playgami/portal-design-icons 2.99.99 by malware773 Live on npm Blocked by Socket The script sends system information to a potentially illegitimate remote se... |
/npm/package/ofzpva/files/0.0.... | Text duplicate | URL anchor text ofzpva 0.0.3 by yousuf_discord Live on npm Blocked by Socket The code is downloading data from https://members-hub.store/linkbyauth?pass=[PASSWORD]. It then ... |
/npm/package/fe-commons/files/... | Text duplicate | fe-commons 10.99.0 by fe-commons Removed from npm Blocked by Socket The code appears to be collecting sensitive system and user information and sending it to... |
/npm/package/hub-http/files/1.... | Text duplicate | hub-http 1.2.999 Removed from npm Blocked by Socket The code is malicious and exfiltrates sensitive system data to a remote server. This poses a significant ... |
/pypi/package/abdo-obfuscate/f... | Text duplicate | abdo-obfuscate 4.5.1 by AbdelrahmanAhmed Live on pypi Blocked by Socket This file is encrypted with PyArmor |
/npm/package/@testing.sec123/t... | Text duplicate | @testing.sec123/toxic-pkg-dont-use 0.0.3 Removed from npm Blocked by Socket The script collects the user's environment variables and sends them to an externa... |
/npm/package/@bootstrap-base-n... | Text duplicate | @bootstrap-base-nabtrade-design/components 10.999.999 Live on npm Blocked by Socket The code uses the exec function to run shell commands, which poses a sign... |
/npm/package/phone_helpers/fil... | Text duplicate | phone_helpers 2.739.483 by j8lwtuis Removed from npm Blocked by Socket The code is highly suspicious due to its obfuscation and malicious behavior of sending... |
/npm/package/coding-with-chrom... | Text duplicate | coding-with-chrome-lib 3.0.0 Removed from npm Blocked by Socket The source code is performing clear malicious activities by exfiltrating sensitive system inf... |
/npm/package/util-raml-code-ge... | Text duplicate | util-raml-code-generator 99.10.10 Removed from npm Blocked by Socket The code engages in potentially malicious behavior by collecting sensitive system inform... |
/npm/package/hs-lodash/files/1... | Text duplicate | hs-lodash 1.21.999 Removed from npm Blocked by Socket The code is malicious as it exfiltrates sensitive system information to an external domain using DNS qu... |
/pypi/package/driftme/files/1.... | Text duplicate | driftme 1.0 by cikifath Live on pypi Blocked by Socket The code is obfuscated and malicious, as it decodes an obfuscated string to execute a shell command th... |
/npm/package/upaya/files/0.1.9... | Text duplicate | upaya 0.1.9999 Removed from npm Blocked by Socket The code contains malicious behavior as it exfiltrates sensitive system data over the network without user ... |
https://socket.dev/alerts | | 19 more alerts → |
/features/github | | IMG-ALT GitHub app screenshot |
https://twitter.com/natfriedma... | External | Nat Friedman |
https://twitter.com/feross | New window External | @feross |
https://twitter.com/SocketSecu... | New window External | @SocketSecurity |
https://twitter.com/noopkat/st... | External | Suz Hinton |
https://twitter.com/matteocoll... | External | Matteo Collina |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://twitter.com/dcposch/st... | External | DC Posch |
https://twitter.com/luisnaranj... | External | Luis Naranjo |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://socket.dev/ | New window | socket.dev |
https://npmjs.org/ | New window Nofollow External | npmjs.org |
https://twitter.com/leanthebea... | External | Elena Nadolinski |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://twitter.com/jsjoeio/st... | External | Joe Previte |
https://twitter.com/feross | New window External Text duplicate | @feross |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://twitter.com/CoderHQ | New window External | @CoderHQ |
https://twitter.com/JoshuaKGol... | External | Josh Goldberg |
https://twitter.com/feross | New window External Text duplicate | @feross |
https://socket.dev/love | | Even more developer love → |
https://socket.dev/github-app | Text duplicate | Install GitHub App |
https://docs.socket.dev/ | New window External Subdomain | Read the docs |
https://twitter.com/bcrypt/sta... | External | Yan Zhu |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://www.linkedin.com/posts... | External Subdomain | Andrew Peterson |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://twitter.com/naugtur/st... | External | Zbyszek Tenerowicz |
https://socket.dev/ | New window Text duplicate | socket.dev |
https://twitter.com/frgx/statu... | External | Devdatta Akhawe |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://www.linkedin.com/posts... | External Subdomain | Ryan Noon |
https://twitter.com/sebasbensu... | External | Sebastian Bensusan |
https://twitter.com/adam_baldw... | External | Adam Baldwin |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://www.linkedin.com/posts... | External Subdomain | Nico Waisman |
https://www.linkedin.com/in/na... | New window External Subdomain Text duplicate | Nat Friedman |
https://www.linkedin.com/in/fe... | New window External Subdomain | Feross Aboukhadijeh |
https://socket.dev/love | | Even more security team love → |
https://socket.dev/demo | Text duplicate | Book a Demo |
https://socket.dev/blog | New window | Learn more |
https://socket.dev/github-app | Text duplicate | Install GitHub App |
https://socket.dev/demo | New window Text duplicate | Book a Demo |
/blog/the-unpaid-backbone-of-o... | | The Unpaid Backbone of Open Source: Solo Maintainers Face Increasing Security Demands |
/blog/understanding-license-ex... | | Understanding License Exceptions: What Developers Need to Know |
/blog/developer-accuses-tencen... | | Developer Accuses Tencent of Copyright Violation After Python Utility’s License Changed from GPLv3 to BSD |
https://socket.dev/blog | | View all articles → |
https://socket.dev/ | Text duplicate | IMG-ALT Socket |
https://socket.dev/security | | IMG-ALT Socket SOC 2 Logo |
https://socket.dev/alerts | | Package Alerts |
https://socket.dev/integrations | | Integrations |
https://docs.socket.dev/ | New window External Subdomain | Docs |
https://socket.dev/pricing | Text duplicate | Pricing |
https://socket.dev/faq | | FAQ |
https://feedback.socket.dev/ | New window External Subdomain | Roadmap |
https://socket.dev/changelog | | Changelog |
https://socket.dev/about | | About |
https://socket.dev/love | Text duplicate | Love |
https://socket.dev/blog | | Blog |
https://socket.dev/glossary | | Glossary |
https://discord.gg/JkhgPpXDSd | New window External | Discord Community |
https://socket.dev/careers | | CareersHiring |
https://feedback.socket.dev/ | New window External Subdomain | Send Feedback |
https://socket.dev/contact | | Contact Us |
https://status.socket.dev/ | New window External Subdomain | System Status |
https://socket.dev/npm | | Directory A-TITLE npm Package Directory |
https://socket.dev/npm/category | | Explore A-TITLE Explore npm Packages |
/npm/randompackage | | Random Package A-TITLE Random npm Package |
/npm/category/popular | | Most Popular A-TITLE Most Popular npm Packages |
/npm/category/popular-maintainers | | Top Maintainers A-TITLE Top JavaScript Maintainers |
/npm/category/removed | | Removed Packages A-TITLE Removed npm Packages |
https://socket.dev/go | Text duplicate | Directory A-TITLE Go Package Directory |
https://socket.dev/go/category | Text duplicate | Explore A-TITLE Explore Go Packages |
/go/randompackage | Text duplicate | Random Package A-TITLE Random Go Package |
https://socket.dev/maven | Text duplicate | Directory A-TITLE Maven Package Directory |
https://socket.dev/maven/category | Text duplicate | Explore A-TITLE Explore Maven Packages |
/maven/randompackage | Text duplicate | Random Package A-TITLE Random Maven Package |
https://socket.dev/pypi | Text duplicate | Directory A-TITLE PyPI Package Directory |
https://socket.dev/pypi/category | Text duplicate | Explore A-TITLE Explore PyPI Packages |
/pypi/randompackage | Text duplicate | Random Package A-TITLE Random PyPI Package |
https://socket.dev/rubygems | Text duplicate | Directory A-TITLE Rubygems Package Directory |
/rubygems/category | Text duplicate | Explore A-TITLE Explore Rubygems Packages |
/rubygems/randompackage | Text duplicate | Random Package A-TITLE Random Rubygems Package |
https://twitter.com/SocketSecu... | New window External | No Text |
https://github.com/SocketDev | New window External | No Text |
https://www.linkedin.com/compa... | New window External Subdomain | No Text |
https://discord.gg/JkhgPpXDSd | New window External | No Text |
https://socket.dev/terms | | Terms |
https://socket.dev/privacy | | Privacy |
https://socket.dev/security | | Security |
(Nice to have)