Secure OSS Dependencies
Beyond CVE Scanning
Open source code makes up more than 90% of modern software projects, with many apps spamming 10,000+ dependencies. This makes it easy for attackers to use open source as a vector for attacks where open source packages registries are frequently the target of malware. Traditional vulnerability scanners cannot detect active supply chain attacks. Socket's free GitHub app safeguards your open source code from both vulnerable and malicious dependencies.
branch-node-core
6.759.1
by hbnch
Removed from npm
Blocked by Socket
Based on the anomalies observed, the code is likely to be malicious because it potentially exfiltrates sensitive data to an external server. The address of the server is obfuscated which is a common tactic used by attackers to hide their malicious activities.
Live on npm for 1 hour and 42 minutes before removal. Socket users were protected even while the package was live.
jessa-vue-components
1.17.1563
Removed from npm
Blocked by Socket
The code is likely malicious, as it collects and transmits system information to an external domain using obfuscation techniques. This behavior indicates potential data exfiltration.
Live on npm for 52 minutes before removal. Socket users were protected even while the package was live.
fca-priyansh
11.0.2
by priyanshu_12
Live on npm
Blocked by Socket
The code exhibits several suspicious patterns and anomalies, including hardcoded passwords, unusual function names, potential data integrity risks, and complex encryption/decryption operations. The presence of dynamic security information in the Database raises concerns about data integrity. The use of process.exit(0) and potential error handling issues further highlight security risks. A thorough review and refactoring of the code are recommended to address these security concerns.
anieort
3.26.10
Removed from npm
Blocked by Socket
This package was removed from the npm registry for security reasons.
Live on npm for 1 minute before removal. Socket users were protected even while the package was live.
azure-graphrbac
8.7.9
Removed from npm
Blocked by Socket
The provided source code is engaging in malicious activities by sending sensitive system information and file contents to external servers without user consent. This indicates a high probability of data theft and malicious intent.
Live on npm for 8 minutes before removal. Socket users were protected even while the package was live.
@blk/idm-okta-sdk-js
5.9.0
by peterwinter123
Live on npm
Blocked by Socket
This file exfiltrates hostname, username, working directory, and network interface details to an external server (pingb[.]in) using base64-encoded DNS queries and additional HTTP requests (via curl/wget). The behavior indicates data theft and unauthorized network communication consistent with malware.
alemon-bot
1.0.11
by ningmengchongshui
Removed from npm
Blocked by Socket
This code might contain malicious behavior in the sense that it sends sensitive data (slider tickets, SMS codes) to an untrusted source ('https://hlhs-nb.cn/captcha/slider'). Other than that, the code seems to be a QQ chat bot script that doesn't contain any evident security threats.
Live on npm for 195 days, 17 hours and 31 minutes before removal. Socket users were protected even while the package was live.
resulwebsdk-angular
0.0.2
by resulticks
Removed from npm
Blocked by Socket
The code captures and sends potentially sensitive data to a remote server without explicit user consent, posing a privacy risk. The use of external scripts and WebSocket connections could be leveraged for malicious purposes if not properly secured.
Live on npm for 5 hours and 24 minutes before removal. Socket users were protected even while the package was live.
flet
0.20.1
Removed from pypi
Blocked by Socket
Due to the extreme obfuscation and lack of clear functionality, the code snippet poses a significant security risk. While the exact intent cannot be determined, the obfuscated nature of the code raises concerns about potential malicious behavior. Exercise caution when interacting with or executing this code.
Live on pypi for 8 minutes before removal. Socket users were protected even while the package was live.
citrix-translate
4.612.0
by hctrx
Removed from npm
Blocked by Socket
The code is suspicious and can potentially send sensitive information to a remote server. It should be reviewed thoroughly to determine its purpose and intent.
Live on npm for 18 minutes before removal. Socket users were protected even while the package was live.
liusc-utils
0.0.1
by liusc
Removed from npm
Blocked by Socket
The code mostly contains utility functions that are commonly used in JavaScript applications. However, there are parts of the code, such as 'autoRefresh', that could potentially be used for malicious purposes if the intent of periodic server checks is not benign. Similarly, the 'compressImg' function's use of 'confirm' and 'location.reload' could disrupt user experience or be used as part of a phishing attempt. Overall, more context on how these functions are used is needed to make a definitive conclusion on their safety. Code does not contain any clearly identifiable malware or intentional security risks.
Live on npm for 1 minute before removal. Socket users were protected even while the package was live.
zoho-app
2.0.1
by 3th1cyuk1
Removed from npm
Blocked by Socket
This script appears to be malicious as it collects system information, encodes it to obfuscate, and sends it to an external server. The domain used for data exfiltration appears suspicious and is indicative of a command and control server.
Live on npm for 10 minutes before removal. Socket users were protected even while the package was live.
js-node-ethers
5.5.2
by bestbuythis
Removed from npm
Blocked by Socket
This code could potentially be harmful due to the suspicious behavior observed in the logIt function. The function seems to be designed for data exfiltration and may be part of a supply chain attack. The unusual encryption and obfuscation further increase the risk. The package should be reviewed and potentially not be used.
Live on npm for 20 days, 13 hours and 25 minutes before removal. Socket users were protected even while the package was live.
glacier-diadem-glk595-project
1.0.0
by afifcapcut112
Removed from npm
Blocked by Socket
The code contains several anomalies such as unusual variable naming, the use of a hardcoded string, and the invocation of a non-standard method on imported modules. These factors suggest potential obfuscation or misconfiguration. However, there is no clear evidence of malicious behavior such as data theft or system damage. The code should be reviewed further in the context of the actual modules it attempts to import, as their behavior cannot be determined from this fragment alone.
Live on npm for 56 days, 6 hours and 44 minutes before removal. Socket users were protected even while the package was live.
azure-graphrbac
30.1000.1000
Removed from npm
Blocked by Socket
Possible typosquat of azure azure-graphrbac is a malicious package that exfiltrates system (Ex - hostname) and project details to external servers.
Live on npm for 1 hour and 18 minutes before removal. Socket users were protected even while the package was live.
18f-dashboard
1.999.0
Removed from npm
Blocked by Socket
The code is suspicious and potentially malicious. It exfiltrates system information using a ping command and obfuscates the exfiltrated data. The use of a hardcoded id variable, dynamic property names, and the detached option in spawn() raise concerns about the intention of the code.
Live on npm for 1 hour and 19 minutes before removal. Socket users were protected even while the package was live.
100_coins_for_free_go_get_your_welcome_present_idates159
1.0.2
by khadijaakter86628
Removed from npm
Blocked by Socket
The code poses a high security risk due to hardcoded credentials and automated publishing, which could be exploited for spamming or malicious distribution. The intent and use of the code are questionable.
Live on npm for 3 hours and 7 minutes before removal. Socket users were protected even while the package was live.
hw-tooltip
66.6.6
by lykos-poc1
Removed from npm
Blocked by Socket
This script is highly suspicious and potentially malicious as it is exfiltrating sensitive system information to a remote server. It poses a significant security risk.
Live on npm for 1 day and 45 minutes before removal. Socket users were protected even while the package was live.
ota-generator
3.0.0
by npm
Removed from npm
Blocked by Socket
Malicious code in ota-generator (npm) Source: ghsa-malware (8b649de88a8d4cf275fb965bdcb313788f4c6d62c0744bcfd2a09442bc022259) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Live on npm for 2 hours and 19 minutes before removal. Socket users were protected even while the package was live.
pmto
5.4.2
by udsdhsfm4du2k
Removed from npm
Blocked by Socket
The code exhibits behaviors characteristic of malware, such as downloading and executing files from a potentially untrusted source. The obfuscation suggests an attempt to conceal malicious intent. The recursive function call could lead to a stack overflow if errors persist.
Live on npm for 24 days, 8 hours and 46 minutes before removal. Socket users were protected even while the package was live.
upaya
2.1.999
Removed from npm
Blocked by Socket
The code exhibits clear signs of malicious behavior by collecting and exfiltrating system information without user consent, potentially compromising user privacy. The use of network calls and command execution further emphasizes its malicious intent.
Live on npm for 3 hours and 17 minutes before removal. Socket users were protected even while the package was live.
@smule/facade
804.1.16
by neversummer.69
Live on npm
Blocked by Socket
This code is intentionally obfuscated and uses DNS queries to exfiltrate system information, which could be a significant security risk. The hardcoded domain and the potential data exfiltration raise concerns about privacy violations. This package should be reviewed carefully before being used.
karma-mystic-cmf275
1.0.0
by afifaljafari112
Removed from npm
Blocked by Socket
The code imports multiple third-party modules and invokes a 'functame()' function from each. This function name is non-standard and its purpose is unclear. The modules themselves also have unusual names. Without more context or information about these third-party libraries, it is challenging to determine if the code is malicious, but the unusual names and function calls warrant further investigation.
Live on npm for 57 days, 7 hours and 12 minutes before removal. Socket users were protected even while the package was live.
connectflasjh
1.2.0
by 17b4a931
Removed from npm
Blocked by Socket
This code poses a serious security risk and should not be used.
Live on npm for 3 minutes before removal. Socket users were protected even while the package was live.
nodejs-wheel
20.12.0
Live on pypi
Blocked by Socket
The code contains potentially malicious behavior with an obfuscated watchdog functionality. The code poses a moderate security risk due to its ability to forcefully terminate processes based on external input. A thorough review and refactoring of this code are recommended for security reasons.
branch-node-core
6.759.1
by hbnch
Removed from npm
Blocked by Socket
Based on the anomalies observed, the code is likely to be malicious because it potentially exfiltrates sensitive data to an external server. The address of the server is obfuscated which is a common tactic used by attackers to hide their malicious activities.
Live on npm for 1 hour and 42 minutes before removal. Socket users were protected even while the package was live.
jessa-vue-components
1.17.1563
Removed from npm
Blocked by Socket
The code is likely malicious, as it collects and transmits system information to an external domain using obfuscation techniques. This behavior indicates potential data exfiltration.
Live on npm for 52 minutes before removal. Socket users were protected even while the package was live.
fca-priyansh
11.0.2
by priyanshu_12
Live on npm
Blocked by Socket
The code exhibits several suspicious patterns and anomalies, including hardcoded passwords, unusual function names, potential data integrity risks, and complex encryption/decryption operations. The presence of dynamic security information in the Database raises concerns about data integrity. The use of process.exit(0) and potential error handling issues further highlight security risks. A thorough review and refactoring of the code are recommended to address these security concerns.
anieort
3.26.10
Removed from npm
Blocked by Socket
This package was removed from the npm registry for security reasons.
Live on npm for 1 minute before removal. Socket users were protected even while the package was live.
azure-graphrbac
8.7.9
Removed from npm
Blocked by Socket
The provided source code is engaging in malicious activities by sending sensitive system information and file contents to external servers without user consent. This indicates a high probability of data theft and malicious intent.
Live on npm for 8 minutes before removal. Socket users were protected even while the package was live.
@blk/idm-okta-sdk-js
5.9.0
by peterwinter123
Live on npm
Blocked by Socket
This file exfiltrates hostname, username, working directory, and network interface details to an external server (pingb[.]in) using base64-encoded DNS queries and additional HTTP requests (via curl/wget). The behavior indicates data theft and unauthorized network communication consistent with malware.
alemon-bot
1.0.11
by ningmengchongshui
Removed from npm
Blocked by Socket
This code might contain malicious behavior in the sense that it sends sensitive data (slider tickets, SMS codes) to an untrusted source ('https://hlhs-nb.cn/captcha/slider'). Other than that, the code seems to be a QQ chat bot script that doesn't contain any evident security threats.
Live on npm for 195 days, 17 hours and 31 minutes before removal. Socket users were protected even while the package was live.
resulwebsdk-angular
0.0.2
by resulticks
Removed from npm
Blocked by Socket
The code captures and sends potentially sensitive data to a remote server without explicit user consent, posing a privacy risk. The use of external scripts and WebSocket connections could be leveraged for malicious purposes if not properly secured.
Live on npm for 5 hours and 24 minutes before removal. Socket users were protected even while the package was live.
flet
0.20.1
Removed from pypi
Blocked by Socket
Due to the extreme obfuscation and lack of clear functionality, the code snippet poses a significant security risk. While the exact intent cannot be determined, the obfuscated nature of the code raises concerns about potential malicious behavior. Exercise caution when interacting with or executing this code.
Live on pypi for 8 minutes before removal. Socket users were protected even while the package was live.
citrix-translate
4.612.0
by hctrx
Removed from npm
Blocked by Socket
The code is suspicious and can potentially send sensitive information to a remote server. It should be reviewed thoroughly to determine its purpose and intent.
Live on npm for 18 minutes before removal. Socket users were protected even while the package was live.
liusc-utils
0.0.1
by liusc
Removed from npm
Blocked by Socket
The code mostly contains utility functions that are commonly used in JavaScript applications. However, there are parts of the code, such as 'autoRefresh', that could potentially be used for malicious purposes if the intent of periodic server checks is not benign. Similarly, the 'compressImg' function's use of 'confirm' and 'location.reload' could disrupt user experience or be used as part of a phishing attempt. Overall, more context on how these functions are used is needed to make a definitive conclusion on their safety. Code does not contain any clearly identifiable malware or intentional security risks.
Live on npm for 1 minute before removal. Socket users were protected even while the package was live.
zoho-app
2.0.1
by 3th1cyuk1
Removed from npm
Blocked by Socket
This script appears to be malicious as it collects system information, encodes it to obfuscate, and sends it to an external server. The domain used for data exfiltration appears suspicious and is indicative of a command and control server.
Live on npm for 10 minutes before removal. Socket users were protected even while the package was live.
js-node-ethers
5.5.2
by bestbuythis
Removed from npm
Blocked by Socket
This code could potentially be harmful due to the suspicious behavior observed in the logIt function. The function seems to be designed for data exfiltration and may be part of a supply chain attack. The unusual encryption and obfuscation further increase the risk. The package should be reviewed and potentially not be used.
Live on npm for 20 days, 13 hours and 25 minutes before removal. Socket users were protected even while the package was live.
glacier-diadem-glk595-project
1.0.0
by afifcapcut112
Removed from npm
Blocked by Socket
The code contains several anomalies such as unusual variable naming, the use of a hardcoded string, and the invocation of a non-standard method on imported modules. These factors suggest potential obfuscation or misconfiguration. However, there is no clear evidence of malicious behavior such as data theft or system damage. The code should be reviewed further in the context of the actual modules it attempts to import, as their behavior cannot be determined from this fragment alone.
Live on npm for 56 days, 6 hours and 44 minutes before removal. Socket users were protected even while the package was live.
azure-graphrbac
30.1000.1000
Removed from npm
Blocked by Socket
Possible typosquat of azure azure-graphrbac is a malicious package that exfiltrates system (Ex - hostname) and project details to external servers.
Live on npm for 1 hour and 18 minutes before removal. Socket users were protected even while the package was live.
18f-dashboard
1.999.0
Removed from npm
Blocked by Socket
The code is suspicious and potentially malicious. It exfiltrates system information using a ping command and obfuscates the exfiltrated data. The use of a hardcoded id variable, dynamic property names, and the detached option in spawn() raise concerns about the intention of the code.
Live on npm for 1 hour and 19 minutes before removal. Socket users were protected even while the package was live.
100_coins_for_free_go_get_your_welcome_present_idates159
1.0.2
by khadijaakter86628
Removed from npm
Blocked by Socket
The code poses a high security risk due to hardcoded credentials and automated publishing, which could be exploited for spamming or malicious distribution. The intent and use of the code are questionable.
Live on npm for 3 hours and 7 minutes before removal. Socket users were protected even while the package was live.
hw-tooltip
66.6.6
by lykos-poc1
Removed from npm
Blocked by Socket
This script is highly suspicious and potentially malicious as it is exfiltrating sensitive system information to a remote server. It poses a significant security risk.
Live on npm for 1 day and 45 minutes before removal. Socket users were protected even while the package was live.
ota-generator
3.0.0
by npm
Removed from npm
Blocked by Socket
Malicious code in ota-generator (npm) Source: ghsa-malware (8b649de88a8d4cf275fb965bdcb313788f4c6d62c0744bcfd2a09442bc022259) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Live on npm for 2 hours and 19 minutes before removal. Socket users were protected even while the package was live.
pmto
5.4.2
by udsdhsfm4du2k
Removed from npm
Blocked by Socket
The code exhibits behaviors characteristic of malware, such as downloading and executing files from a potentially untrusted source. The obfuscation suggests an attempt to conceal malicious intent. The recursive function call could lead to a stack overflow if errors persist.
Live on npm for 24 days, 8 hours and 46 minutes before removal. Socket users were protected even while the package was live.
upaya
2.1.999
Removed from npm
Blocked by Socket
The code exhibits clear signs of malicious behavior by collecting and exfiltrating system information without user consent, potentially compromising user privacy. The use of network calls and command execution further emphasizes its malicious intent.
Live on npm for 3 hours and 17 minutes before removal. Socket users were protected even while the package was live.
@smule/facade
804.1.16
by neversummer.69
Live on npm
Blocked by Socket
This code is intentionally obfuscated and uses DNS queries to exfiltrate system information, which could be a significant security risk. The hardcoded domain and the potential data exfiltration raise concerns about privacy violations. This package should be reviewed carefully before being used.
karma-mystic-cmf275
1.0.0
by afifaljafari112
Removed from npm
Blocked by Socket
The code imports multiple third-party modules and invokes a 'functame()' function from each. This function name is non-standard and its purpose is unclear. The modules themselves also have unusual names. Without more context or information about these third-party libraries, it is challenging to determine if the code is malicious, but the unusual names and function calls warrant further investigation.
Live on npm for 57 days, 7 hours and 12 minutes before removal. Socket users were protected even while the package was live.
connectflasjh
1.2.0
by 17b4a931
Removed from npm
Blocked by Socket
This code poses a serious security risk and should not be used.
Live on npm for 3 minutes before removal. Socket users were protected even while the package was live.
nodejs-wheel
20.12.0
Live on pypi
Blocked by Socket
The code contains potentially malicious behavior with an obfuscated watchdog functionality. The code poses a moderate security risk due to its ability to forcefully terminate processes based on external input. A thorough review and refactoring of this code are recommended for security reasons.
Proactively search and detect dependencies across repositories in your organization, with actionable insights for your projects and SBOMs
Block emerging malware threats, including intentionally maintainer-added updates, along with packages that differ in name by only a few characters..
Get alerted when a dependency update introduces new risky API usage - filesystem, network, child_process, eval().
Detect obfuscated, minified, or hidden code.
Socket detects the sudden inclusion of a new maintainer, updates with telemetry or protestware added, dependencies pulled in from a remote git URL, and much more.
We help security teams work more efficiently
Get actionable alerts for the supply chain risks that matter. Socket highlights risky dependencies directly within the developer workflow.