#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Privacy
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
Socket: PyPI and npm payment SDK malware compromises CI/CD
·
Developer Tech
·
July 8, 2026, 4:02 p.m.
APIs
Build & Ship
CI/CD & Release Engineering
Cybersecurity & Development
npm
ci/cd
pypi
Developer Tools
Summary
Socket reports that 17 malicious payment SDK packages were found on npm and PyPI, designed to harvest developer credentials and CI/CD variables, posing a threat to engineering teams using PaySafe and Skrill.
Read full post on www.developer-tech.com →
MORE POSTS LIKE THIS
How to Publish Python Packages with Digital Attestations
Python Developer Tooling Handbook – pydevtools.com ·
Sep 10, 2026
Python
ci/cd
npm supply-chain attack hits 400+ packages and steals developer credentials
Developer Tech ·
Aug 6, 2026
CI/CD & Release Engineering
Cybersecurity & Development
Buildline: one timeline for your whole build, merging cargo's --timings and ninja's log
Users Rust Lang ·
Jul 22, 2026
Open Source
ci/cd
github: Dependabot no longer infers .npmrc
Sujith Quintelier ·
Jul 1, 2026
npm
github
Cooldown or Compromise: The 7-Day Rule for npm and PyPI
Research Eye ·
Jun 23, 2026
Tech blog
npm
What is npm doing to protect the JavaScript ecosystem – and is it enough?
Thestack ·
Jun 16, 2026
Cybersecurity
npm
Discover more posts →
AUTHOR
Advertise
Sponsor diff.blog
Put your product in front of developers who read and write about their craft. One exclusive sponsor at a time.
Become a sponsor →
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google
By continuing, you agree to our
Privacy Policy
.