Vendor
Socket
- First Reported
- Aug 4, 2026
- Latest Reported
- Aug 31, 2026
Reported Context (3)
- Socket’s Threat Research Team found 13 malicious Composer theme packages on Packagist, published across five vendor namespaces, that inject JavaScript into every page of the Vietnamese movie and comic streaming sites 13 Malicious Packagist Themes Deliver iOS Spyware and Steal Crypto Wallet Seeds
- Socket’s Threat Research Team analyzed a coordinated supply chain attack affecting three legitimate Rust crates maintained by David Roundy (droundy): Malicious Rust Crates Deliver Cross-Platform Backdoor During Builds
- Socket’s Threat Research Team is tracking an active supply chain compromise affecting the widely used keyv and cacheable npm packages. On August 4, 2026, at least ten packages beginning with the keyv and cacheable Active npm Supply-Chain Attack Compromises Keyv and Cacheable Packages
CVE (3)
Malware (3)
People (2)
MITRE ATT&CK (27)
Vendors (3)
Products (31)
Tools (7)
Industries (2)
Countries (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.