<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — Socket</title><description>Articles on devtake.dev covering Socket.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>Mini Shai-Hulud hit PyTorch Lightning. The 11.6M-download PyPI package shipped a credential stealer.</title><link>https://devtake.dev/article/pytorch-lightning-pypi-compromise-mini-shai-hulud/</link><guid isPermaLink="true">https://devtake.dev/article/pytorch-lightning-pypi-compromise-mini-shai-hulud/</guid><description>Two malicious lightning releases hit PyPI on April 30. The 42-minute window was enough to ship an RSA-encrypted infostealer to ML developers worldwide.</description><pubDate>Sat, 02 May 2026 09:00:00 GMT</pubDate><category>security</category><category>pytorch-lightning</category><category>pypi</category><category>supply-chain</category><category>mini-shai-hulud</category><category>credential-theft</category><category>python</category><category>ml</category><category>security</category><author>luca-reinhardt</author></item><item><title>Another npm worm: CanisterWorm hits 16 Namastex packages and reaches PyPI on the same hop</title><link>https://devtake.dev/article/canisterworm-namastex-npm-pypi-supply-chain/</link><guid isPermaLink="true">https://devtake.dev/article/canisterworm-namastex-npm-pypi-supply-chain/</guid><description>Socket flagged a self-propagating worm in @automagik/genie, pgserve, and 14 sibling Namastex Labs packages. It steals 40 credential categories and republishes itself.</description><pubDate>Tue, 28 Apr 2026 16:30:00 GMT</pubDate><category>security</category><category>npm</category><category>supply-chain</category><category>canisterworm</category><category>security</category><category>namastex</category><category>teampcp</category><category>pypi</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>Bitwarden CLI got backdoored for 90 minutes. The worm calls itself &apos;Shai-Hulud: The Third Coming.&apos;</title><link>https://devtake.dev/article/bitwarden-cli-shai-hulud-npm-worm/</link><guid isPermaLink="true">https://devtake.dev/article/bitwarden-cli-shai-hulud-npm-worm/</guid><description>A malicious @bitwarden/cli@2026.4.0 hit npm on April 22. The payload steals npm tokens, cloud secrets, and Claude Code credentials, then self-replicates.</description><pubDate>Thu, 23 Apr 2026 19:00:00 GMT</pubDate><category>security</category><category>bitwarden</category><category>shai-hulud</category><category>npm</category><category>supply-chain</category><category>worm</category><category>credential-theft</category><category>checkmarx</category><category>cicd</category><author>luca-reinhardt</author></item><item><title>Inside GitHub&apos;s fake star economy: 6 million bought stars and how to spot them</title><link>https://devtake.dev/article/github-fake-star-economy/</link><guid isPermaLink="true">https://devtake.dev/article/github-fake-star-economy/</guid><description>A Carnegie Mellon study counted 6 million suspected fake stars across 18,617 GitHub repos. Here&apos;s what the StarScout research actually found and how to read a star count now.</description><pubDate>Mon, 20 Apr 2026 16:00:00 GMT</pubDate><category>open-source</category><category>github</category><category>fake-stars</category><category>starscout</category><category>open-source</category><category>software-research</category><category>icse-2026</category><category>supply-chain</category><category>ai-repos</category><author>soren-vanek</author></item></channel></rss>