Sign in

Ahmad Nassri

@ahmadnassri.com
794 followers 45 following 45 posts

CTO @ Socket.dev

PostsRepliesMedia
Reposted by Ahmad Nassri
Socket @socket.dev · 05/08/2026
A preview of where autonomous hacking may be heading: During a UK cyber test, a Mythos 5 agent used sockpuppets, spearphishing emails, and prompt injection to try to get an open source maintainer to merge malware. socket.dev/blog/ai-agen... #OpenSource #Cybersecurity
socket.dev
UK Cyber Test: AI Agent Attempted to Social Engineer Open So...
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.
072
Reposted by Ahmad Nassri
Feross @feross.bsky.social · 04/08/2026
🚀 Socket is now available in the AWS Security Hub Extended plan. Apply committed AWS spend, first month free. Also new: Socket Firewall bills on unique artifacts checked, not bandwidth or downloads. Pin 200 packages, install them a million times, pay for 200. socket.dev/blog/aws-sec...
socket.dev
AWS Security Hub Adds Socket for Supply Chain Security - Soc...
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
094
Ahmad Nassri @ahmadnassri.com · 04/08/2026
🚨 An npm worm is spreading live, while half of the security industry is at #BlackHat in Vegas. talk about timing! @socket.dev is now tracking 2,234 malicious package artifacts across 444 unique packages in the keyv/cacheable compromise. Average detection time: 5 min 18 sec after publication
socket.dev
Popular npm Packages in the keyv and Cacheable Namespaces Co...
Popular npm packages keyv and cacheable compromised.
0163
Reposted by Ahmad Nassri
Feross @feross.bsky.social · 01/08/2026
Excited by the approach Packagist has taken here, and so incredibly excited for Socket to be a launch sponsor. socket.dev/blog/socket-...
socket.dev
Socket Is Sponsoring Composer and Packagist - Socket
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secur...
033
Reposted by Ahmad Nassri
Socket @socket.dev · 17/07/2026
The White House launched a new initiative to coordinate AI-discovered vulnerabilities across government, critical infrastructure, and open source. No operating plan is public yet, even as federal vulnerability programs face massive backlogs and failures. socket.dev/blog/white-h...
socket.dev
White House Launches Gold Eagle Initiative to Manage Surge i...
The White House’s Gold Eagle Initiative aims to coordinate AI-discovered vulnerabilities, validate findings, and accelerate patching across critical s...
061
Reposted by Ahmad Nassri
Socket @socket.dev · 17/06/2026
New research: We’re seeing more packages designed to trip up AI malware scanners. This new package uses prompt-injection-style comments, safety-triggering content, context flooding, and obfuscated JS to probe where scanners refuse, truncate, or miss the code that matters. socket.dev/blog/npm-pac...
socket.dev
npm Package Uses Prompt Injection and Token Flooding to Disr...
A new npm package tests AI malware scanners with prompt injection, safety-triggering comments, context flooding, and obfuscated JavaScript.
171
Reposted by Ahmad Nassri
Socket @socket.dev · 10/06/2026
🔥 Socket Firewall is now built into Replit's AI-powered development experience. It’s already blocking 8K malicious packages/day across builders on the platform, giving Replit users stronger protection by default at the moment dependencies are introduced. socket.dev/blog/socket-...
socket.dev
Socket Partners with Replit to Block Malicious Packages in A...
Replit is integrating Socket Firewall into its AI-powered development experience to help protect builders from malicious open source packages.
062
Reposted by Ahmad Nassri
Socket @socket.dev · 09/06/2026
npm accidentally marked a bunch of one-character packages as security holders, including c, i, n, x, several numbers, and even the - package. The registry confirmed it was a tooling bug and said a rollback is underway. socket.dev/blog/npm-too...
socket.dev
npm Tooling Bug Incorrectly Marks One-Character Packages as ...
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.
063
Reposted by Ahmad Nassri
Socket @socket.dev · 21/05/2026
npm nuked every granular access token that bypasses 2FA after another Mini Shai-Hulud wave compromised hundreds of packages. Good news: staged publishing is now in public preview. socket.dev/blog/npm-inv... #NodeJS #JavaScript
socket.dev
npm Invalidates Granular Access Tokens as Mini Shai-Hulud Sw...
npm invalidated all granular access tokens that bypass 2FA after a fresh Mini Shai-Hulud wave compromised 323 npm packages. Staged publishing also ent...
0262
Reposted by Ahmad Nassri
Peter van der Zee @pvdz.ee · 20/05/2026
Socket raised a C round! (Maybe we should be SoCket now! ok eeew no) All I can see on my part is that I've been having an awesome time working on AI and with AI, detection, and what not. Lucky to be part in the right place at the right time :D bsky.app/profile/fero...
092
Reposted by Ahmad Nassri
Feross @feross.bsky.social · 20/05/2026
Today is a big day for @socket.dev. We raised a $60M Series C at a $1B valuation, led by Thrive Capital. 20,000+ orgs, 1.5M repos protected, 1,000+ supply chain attacks blocked per week. 3/5 FAANG companies are customers. We're just getting started.
118514
Ahmad Nassri @ahmadnassri.com · 01/05/2026
Today's "Mini Shai-Hulud" supply chain attack is a wild evolution! 1. Cascading, cross-ecosystem propagation (PyPi ➡️ npmjs ➡️ Packagist) 2. Using a JS runtime (Bun) to infect Python and PHP 3. Impersonates Claude in git commits to hide in plain sight 🧵
110
Reposted by Ahmad Nassri
Socket @socket.dev · 25/04/2026
We’re tracking 73 Open VSX sleeper extensions tied to the GlassWorm campaign, with at least 6 already activated to deliver malware. These cloned extensions initially appear benign, then later become malware delivery vehicles through normal updates. socket.dev/blog/73-open...
socket.dev
73 Open VSX Sleeper Extensions Linked to GlassWorm Show New ...
Socket is tracking cloned Open VSX extensions tied to GlassWorm, with several updated from benign-looking sleepers into malware delivery vehicles.
143
Reposted by Ahmad Nassri
Socket @socket.dev · 22/04/2026
🚨 Breaking: Namastex Labs, the team behind Automagik[.]dev, hit with a supply chain attack affecting its npm packages. The malicious versions replicate TeamPCP-style Canister Worm tradecraft, including secret theft, exfiltration, and self-propagation. socket.dev/blog/namaste...
socket.dev
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm...
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
196
Ahmad Nassri @ahmadnassri.com · 10/04/2026
Goosonomics (noun) 🪿 A hypocritical corporate strategy of extracting immense financial value from unpaid, open-source labor, only to later declare OSS "dead" or untrustworthy to justify forking, rebuilding, and rebundling that exact same software as a premium, "safe" product.
1145
Reposted by Ahmad Nassri
Socket @socket.dev · 07/04/2026
"Docker Hardened Images for Node.js, Python, and Rust also include Socket Firewall, which blocks malicious dependencies at install time." Another tool for securing your build pipeline - DHI are free and open source: socket.dev/blog/socket-...
0113
Ahmad Nassri @ahmadnassri.com · 03/04/2026
North Korea is targeting npm maintainers. Not for crypto. For write access to packages downloaded trillions of times a year. Lodash. Fastify. axios. mocha. Node.js core. Even @feross.bsky.social and several @socket.dev engineers! socket.dev/blog/attacke...
socket.dev
Attackers Are Hunting High-Impact Node.js Maintainers in a C...
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
0168
Reposted by Ahmad Nassri
Feross @feross.bsky.social · 02/04/2026
We’re seeing cases where teams can’t explain how they were compromised by the Axios incident because it doesn’t show up in their project's lockfile. The blast radius here is much larger than it looks. Deep dive into the messy reality of modern dependency resolution → socket.dev/blog/hidden-...
socket.dev
The Hidden Blast Radius of the Axios Compromise - Socket
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
01711
Reposted by Ahmad Nassri
Peter van der Zee @pvdz.ee · 01/04/2026
The axios compromise blast radius is much much much bigger than people seem to suspect. The secret: transitive dependencies with open ranges making it extremely obscure and difficult to detect whether you were affected, after the fact.
064
Ahmad Nassri @ahmadnassri.com · 01/04/2026
⚠️ If you're running local mcp servers, you need to do the following: 1. Individually "install" packages you want to use, within a specified directory: (e.g. $HOME/mcp) creating a lockfile 2. Add: "--include-workspace-root --workspace $HOME/mcp --no --offline" to EVERY npx call
293
Ahmad Nassri @ahmadnassri.com · 31/03/2026
📢 ZERO SIGN UP, FREE FOREVER, MALWARE PROTECTION. npm i -g sfw sfw npm install sfw pnpm install sfw yarn install sfw cargo fetch sfw uv pip install socket.dev/blog/introdu...
socket.dev
Introducing Socket Firewall: Free, Proactive Protection for ...
Socket Firewall is a free tool that blocks malicious packages at install time, giving developers proactive protection against rising supply chain atta...
020
Ahmad Nassri @ahmadnassri.com · 31/03/2026
sigh.
010
Ahmad Nassri @ahmadnassri.com · 31/03/2026
🚨 NOT AN EARLY APRIL FOOLS! 🚨 Active supply chain attack on axios@1.14.1. The latest version pulls in plain-crypto-js@4.2.1 -- a brand-new package that didn't exist before today! If you use axios, pin your version and audit your lockfile. Socket's Analysis: socket.dev/blog/axios-n...
socket.dev
Supply Chain Attack on Axios Pulls Malicious Dependency from...
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHu...
011
Reposted by Ahmad Nassri
Socket @socket.dev · 24/03/2026
This is an important situation for every security tool and open source project to monitor right now. cc: @campuscodi.risky.biz @thehackernews.bsky.social @bleepingcomputer.com @techcrunch.com @zackwhittaker.com
011
Ahmad Nassri @ahmadnassri.com · 24/03/2026
These tools are secret + infrastructure + code security scanners by design and used in critical enterprise workflows. If compromised, they risk exposing production environments' secrets with a direct view into where the weak points are. socket.dev/blog/teampcp...
socket.dev
TeamPCP Is Systematically Targeting Security Tools Across th...
TeamPCP is targeting security tools across the OSS ecosystem, turning scanners and CI pipelines into infostealers to access enterprise secrets.
021
Ahmad Nassri @ahmadnassri.com · 24/03/2026
GitHub Actions considered malicious, everybody move back to Jenkin! 🙈 "GitHub’s architecture makes fork commits reachable by SHA from the parent repo" 🚨 amazing breakdown by Rose Security 👏 rosesecurity.dev/2026/03/20/t... #trivy #github #actions #sca #supplychain #security
010
Ahmad Nassri @ahmadnassri.com · 22/03/2026
🚨 AquaSecurity's private source code seems to be fully compromised and in the open, released by the attackers today to github.com/aquasec-com The leak includes private keys credential scripts in the exposed repos. All repos have description: "TeamPCP Owns Aqua Security."
110
Reposted by Ahmad Nassri
Socket @socket.dev · 19/03/2026
In less than 6 months, companies shipping software in Europe face the first Cyber Resilience Act deadline. ENISA's latest advisory on secure package manager use spells out expectations for SBOMs, dependency monitoring, and vulnerability reporting. socket.dev/blog/enisa-t...
socket.dev
ENISA Publishes Technical Advisory on Secure Use of Package ...
ENISA’s new package manager advisory outlines the dependency security practices companies will need to demonstrate as the EU’s Cyber Resilience Act be...
043
Ahmad Nassri @ahmadnassri.com · 16/03/2026
⚠️ UPDATE: we're now tracking 213+ affected package artifacts across this campaign! socket.dev/supply-chain...
socket.dev
GlassWorm v2 - Socket
Socket fights vulnerabilities and provides visibility, defense-in-depth, and proactive supply chain protection for JavaScript, Python, and Go dependencies.
020
Ahmad Nassri @ahmadnassri.com · 16/03/2026
🚨 VSCode & OpenVSX users, take note: The "GlassWorm" campaign has evolved to weaponize the very structure of your IDE Extensions. The @socket.dev Research Team just uncovered over 73 new malicious OpenVSX extensions. Read the full technical breakdown + IOCs on our blog socket.dev/blog/open-vs...
socket.dev
72 Malicious Open VSX Extensions Linked to GlassWorm Campaig...
Since January 31, 2026, we identified at least 72 additional malicious Open VSX extensions, including transitive GlassWorm loader extensions targeting...
000
Ahmad Nassri @ahmadnassri.com · 20/02/2026
Join @socket.dev + @cloudflare.social in a livestream NOW discussing #SANDWORM_MODE the Shai-Hulud-Style npm Worm Hijacking CI Workflows and Poisoning AI Toolchains www.youtube.com/watch?v=OQ6w...
youtube.com
🚨 Active Shai-Hulud–Like npm Supply Chain Attack: SANDWORM_MODE
YouTube video by Socket Security
030
Ahmad Nassri @ahmadnassri.com · 20/02/2026
The @socket.dev team caught super early signals of this attack campaign leading to preemptive shutdown! proud of the team and our advanced threat detection engine! 💪 Thankful for the rapid response and takedown @npmjs.bsky.social @github.com @cloudflare.social 🙏 #shaihulud #SANDWORM_MODE
2124
Reposted by Ahmad Nassri
Feross @feross.bsky.social · 20/02/2026
Incoming news. Stay tuned.
131
Reposted by Ahmad Nassri
Socket @socket.dev · 19/02/2026
Really cool to see @npmjs.bsky.social featuring more security information on package pages, including a link to Socket's analysis! 🤩 Here's what you'll find when you click through → socket.dev/blog/socket-... #NodeJS #JavaScript
094
Reposted by Ahmad Nassri
Socket @socket.dev · 13/02/2026
New Research: Malicious Chrome extension targets Meta Business Suite/Facebook Business Manager, steals TOTP 2FA seeds + codes, and exfiltrates Business Manager exports (People + analytics). Full analysis: socket.dev/blog/malicio...
socket.dev
Malicious Chrome Extension Steals Meta Business Manager Expo...
Chrome extension CL Suite by @CLMasters neutralizes 2FA for Facebook and Meta Business accounts while exfiltrating Business Manager contact and analyt...
022
Reposted by Ahmad Nassri
Socket @socket.dev · 21/01/2026
🚀 Socket Launch Week Day 3: We’re launching supply chain attack campaign tracking in the Socket dashboard!
131
Reposted by Ahmad Nassri
Socket @socket.dev · 24/12/2025
Add this episode to your podcast listening queue during the holidays. 🎧 Socket CTO @ahmadnassri.com talks through practical AI coding workflows, where AI actually helps teams today, and why the biggest shifts are being driven by economics. socket.dev/blog/enginee...
022
Reposted by Ahmad Nassri
Feross @feross.bsky.social · 17/12/2025
Congrats @docker.com! This is the right move for the ecosystem. In case you missed this detail: with Docker Hardened Images teams get secure application dependencies by default. @socket.dev Firewall is built in.
193
Reposted by Ahmad Nassri
Socket @socket.dev · 17/12/2025
🚀 Big News! Docker Hardened Images are now free! We’re partnering with @docker.com to bundle Socket Firewall into supported images, adding supply chain protection during dependency installs and builds. Details → socket.dev/blog/socket-...
socket.dev
Socket Firewall Now Available in Docker Hardened Images - So...
Socket Firewall Free is now bundled into Docker Hardened Images, adding build-time and dependency-install supply chain protection on top of hardened b...
052
Ahmad Nassri @ahmadnassri.com · 17/12/2025
We’re partnering with @docker.com to make software development safer for everyone! Socket Firewall Free is now bundled into Docker Hardened Images, adding build-time and dependency-install supply chain protection for @nodejs.org, @python.org, and @rust-lang.org socket.dev/blog/socket-...
socket.dev
Socket Firewall Now Available in Docker Hardened Images - So...
Socket Firewall Free is now bundled into Docker Hardened Images, adding build-time and dependency-install supply chain protection on top of hardened b...
062
Reposted by Ahmad Nassri
Socket @socket.dev · 16/12/2025
🎁 The Nightmare Before Deployment socket.dev/blog/supply-...
socket.dev
The Nightmare Before Deployment - Socket
Season’s greetings from Socket, and here’s to a calm end of year: clean dependencies, boring pipelines, no surprises.
043
Reposted by Ahmad Nassri
Socket @socket.dev · 02/12/2025
🎙️ Why great products don't always win: Socket CEO @feross.bsky.social breaks down a hard truth for technical founders in this conversation with Vlad Kachur on scaling a security company. Check out the full interview → socket.dev/blog/scaling... #appsec #infosec
013
Ahmad Nassri @ahmadnassri.com · 24/11/2025
Shai-Hulud Déjà vu! 🚨 new wave of supply chain attacks hits npm, impacting widely used packages from AsyncAPI, ENS, Postman, PostHog, and Zapier. socket.dev/blog/shai-hu...
socket.dev
Shai Hulud Strikes Again (v2) - Socket
Another wave of Shai-Hulud campaign has hit npm with more than 500 packages and 700+ versions affected.
030
Reposted by Ahmad Nassri
Feross @feross.bsky.social · 19/11/2025
🚀 Big news for JavaScript teams: Socket now supports Bun and vlt in beta. You no longer have to choose between innovation and security. Commit a bun.lock or vlt-lock.json and Socket gives you full supply chain protection.
1105
Reposted by Ahmad Nassri
Socket @socket.dev · 19/11/2025
Launch Week Day 3: We're announcing beta support for @bun.sh and @vlt.sh package managers in Socket! 🎉 Developers using emerging JavaScript package managers can now rely on Socket for full supply chain security, dependency graph analysis, and accurate SBOMs.
153
Reposted by Ahmad Nassri
Socket @socket.dev · 05/11/2025
Check out Socket CTO @ahmadnassri.com at @workos.bsky.social' Enterprise Ready Conf: Ahmad joined a panel discussing how enterprise security is adapting, as AI speeds up both software development and attacks targeting developer machines. socket.dev/blog/how-ent...
socket.dev
How Enterprise Security Is Adapting to AI-Accelerated Threat...
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.
011
Ahmad Nassri @ahmadnassri.com · 01/11/2025
nothing beats a Syrian breakfast 🤤 @ Damaski Palace maps.app.goo.gl/NWZatN3mgves...
130
Reposted by Ahmad Nassri
Socket @socket.dev · 24/10/2025
🚀 Socket Launch Week Day 5! Malicious packages are infiltrating development environments before they ever reach production. Today we're answering these threats with the release of Socket Firewall Enterprise: configurable, enterprise-grade protection for modern package ecosystems.
121
Reposted by Ahmad Nassri
Feross @feross.bsky.social · 20/10/2025
1️⃣ AI models aren’t just math -- they’re code. And just like npm or PyPI, they can get hacked. Today we’re launching malware scanning for the Hugging Face ecosystem. 🤖🔍 Socket can now detect backdoors and malicious payloads inside AI models themselves. 👇 www.youtube.com/watch?v=9FQy...
youtube.com
Announcing Experimental Malware Scanning for the Hugging Face Ecosystem
YouTube video by Socket Security
2116
Ahmad Nassri @ahmadnassri.com · 20/10/2025
for better security: I use 1password cli with direnv to dynamically load env values (ssh keys, tokens, secrets, etc ...) AWS outage -> 1password thinks it's offline -> can't run anything locally which requires secrets🥲
110