Feross

@feross.bsky.social

🧙‍♂️ Mad scientist • ✨ Founder + CEO @Socket.dev (http://socket.dev) •🌲 Stanford lecturer (http://cs253.stanford.edu) • ❤️ Open source at WebTorrent + StandardJS

🚀 Socket is now available in the AWS Security Hub Extended plan. Apply committed AWS spend, first month free. Also new: Socket Firewall bills on unique artifacts checked, not bandwidth or downloads. Pin 200 packages, install them a million times, pay for 200. socket.dev/blog/aws-sec...

AWS Security Hub Adds Socket for Supply Chain Security - Soc...

Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

socket.dev

🚨 Update: Watching this npm worm propagate in real time, we’re now tracking 2,234 affected package artifacts across 444 unique packages, and it’s still spreading. Average detection time: 5 min and 18 seconds after publication. Our campaign page includes all affected packages/versions.

Socket@socket.dev · yesterday

🚨 Active npm supply chain attack: keyv​@​6.0.0 and 13 other packages have been compromised. keyv alone gets 154M weekly downloads. The worm steals cloud and CI credentials, then uses stolen npm tokens to publish trojanized versions of more packages.

🚨 Another npm worm is live right now. It landed the same week npm turned on publish-time malware scanning, and after npm killed long-lived tokens in favor of OIDC trusted publishing. It propagates through trusted publishing. keyv@6.0.0 even shipped with passing provenance.

After working with the @packagist.com team through recent supply chain attacks, it's clear how much they genuinely care about the health and security of PHP developers. They move fast & show up whenever the ecosystem needs them. If your company depends on Composer or Packagist, please support them.

Socket@socket.dev · 5d ago

Socket is a launch sponsor of the new Composer and @packagist.com sponsorship program. Packagist is critical infrastructure for millions of #PHP developers, and we're proud to fund the work that keeps it secure and open. socket.dev/blog/socket-...

Wild case of what appears to be industrial espionage. The attackers found public code references to Alibaba’s private npm packages, then reused the names for unscoped package lures targeting developers with access to Alibaba’s internal tooling.

Socket@socket.dev · last wk.

A covert npm campaign targeting @alibabagroup.bsky.social developers split its loader across benign-looking packages. Combined, they deployed a cross-platform RAT that poisons AI tool skills for persistence and spreads laterally through DingTalk. socket.dev/blog/npm-rat...

Shai-Hulud's downstream impact is still coming to light. The worm hit tens of thousands of GitHub repos, and the latest breach is Suno, whose leaked source code shows how it scraped YouTube, Deezer, and Genius to train its models. 🎩 First reported by @404media.co. socket.dev/blog/suno-br...

Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu...

A Shai-Hulud infection exposed Suno's source code, which shows the AI music startup stream-ripped tracks to train its models.

socket.dev

🔺 Socket researchers found a malicious Go module posing as a DNS/subdomain scanner. Following that trail exposed 222 GitHub repositories across 190 accounts: fake software projects used to stage Windows RAT and infostealer malware. Full analysis → socket.dev/blog/malicio...

Malicious Go Module Exposes GitHub Malware Lure Network Span...

Socket tracks the activity as Operation “Muck and Load”: a threat actor uses commit-farming workflows, public dead drops, and protected archives to st...

socket.dev

Surreal to see Socket sponsoring NodeConf EU. This is where I gave an impromptu talk on PeerCDN, my first startup, back in 2013, and where I met almost all my Node friends. Awesome to finally pay it forward.

NodeConf.eu@nodeconf.eu · last mo.

🚀Thrilled to announce @socket.dev as #gold Sponsors of #NodeConfEU 2026! 🌟 Socket is a #cybersecurity platform that protects companies from software supply chain attacks. Find out more👉 socket.dev Thank you! Your partnership is helping us create something truly special in the #Node.js community!

🧩 New Research: 152 Chrome "live wallpaper" extensions hid ad tracking behind false privacy disclosures and faked Google search traffic to support ad monetization. The network spanned 38 publisher accounts, 3 backend brands, and ~105K installs. socket.dev/blog/152-chr...

152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fak...

A network of 152 Chrome live wallpaper extensions hid ad tracking and made extension-driven traffic look like Google search clicks.

socket.dev

Andrew Becherer is joining Socket as our first CISO. He was Datadog's first security hire and led security there through its IPO. Socket protects 27,000+ orgs. Andrew will own how we protect ourselves and how we show up for the security teams we serve. socket.dev/blog/andrew-...

Andrew Becherer Joins Socket as Chief Information Security O...

Socket’s first CISO brings deep experience securing high-growth SaaS companies as open source supply chain threats accelerate.

socket.dev