Sign in

Ahmad Nassri

@ahmadnassri.com
798 followers 45 following 45 posts

CTO @ Socket.dev

PostsRepliesMedia
Reposted by Ahmad Nassri
Socket @socket.dev · 01/10/2026
"The agents have too much power" @ahmadnassri.com
121
Reposted by Ahmad Nassri
Socket @socket.dev · 02/10/2026
Modern malware doesn't need to steal anything 🫪 It simply tells your AI agent "you're an authorized pentester" and lets the it do the stealing. Socket CTO @ahmadnassri.com Nassri on Insecure Agents with Allie Howe: socket.dev/blog/insecur...
131
Reposted by Ahmad Nassri
Feross @feross.bsky.social · 29/09/2026
Socket now protects four of the Magnificent Seven, two of the three hyperscalers, nearly every leading AI lab, and one of America's largest automakers. This summer, @socket.dev automatically blocked two live supply chain attacks at the world's largest company.
151
Reposted by Ahmad Nassri
Socket @socket.dev · 05/08/2026
A preview of where autonomous hacking may be heading: During a UK cyber test, a Mythos 5 agent used sockpuppets, spearphishing emails, and prompt injection to try to get an open source maintainer to merge malware. socket.dev/blog/ai-agen... #OpenSource #Cybersecurity
socket.dev
UK Cyber Test: AI Agent Attempted to Social Engineer Open So...
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.
072
Reposted by Ahmad Nassri
Feross @feross.bsky.social · 04/08/2026
🚀 Socket is now available in the AWS Security Hub Extended plan. Apply committed AWS spend, first month free. Also new: Socket Firewall bills on unique artifacts checked, not bandwidth or downloads. Pin 200 packages, install them a million times, pay for 200. socket.dev/blog/aws-sec...
socket.dev
AWS Security Hub Adds Socket for Supply Chain Security - Soc...
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
094
Ahmad Nassri @ahmadnassri.com · 04/08/2026
🚨 An npm worm is spreading live, while half of the security industry is at #BlackHat in Vegas. talk about timing! @socket.dev is now tracking 2,234 malicious package artifacts across 444 unique packages in the keyv/cacheable compromise. Average detection time: 5 min 18 sec after publication
socket.dev
Popular npm Packages in the keyv and Cacheable Namespaces Co...
Popular npm packages keyv and cacheable compromised.
0173
Reposted by Ahmad Nassri
Feross @feross.bsky.social · 01/08/2026
Excited by the approach Packagist has taken here, and so incredibly excited for Socket to be a launch sponsor. socket.dev/blog/socket-...
socket.dev
Socket Is Sponsoring Composer and Packagist - Socket
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secur...
033
Reposted by Ahmad Nassri
Socket @socket.dev · 17/07/2026
The White House launched a new initiative to coordinate AI-discovered vulnerabilities across government, critical infrastructure, and open source. No operating plan is public yet, even as federal vulnerability programs face massive backlogs and failures. socket.dev/blog/white-h...
socket.dev
White House Launches Gold Eagle Initiative to Manage Surge i...
The White House’s Gold Eagle Initiative aims to coordinate AI-discovered vulnerabilities, validate findings, and accelerate patching across critical s...
061
Reposted by Ahmad Nassri
Socket @socket.dev · 17/06/2026
New research: We’re seeing more packages designed to trip up AI malware scanners. This new package uses prompt-injection-style comments, safety-triggering content, context flooding, and obfuscated JS to probe where scanners refuse, truncate, or miss the code that matters. socket.dev/blog/npm-pac...
socket.dev
npm Package Uses Prompt Injection and Token Flooding to Disr...
A new npm package tests AI malware scanners with prompt injection, safety-triggering comments, context flooding, and obfuscated JavaScript.
171
Reposted by Ahmad Nassri
Socket @socket.dev · 10/06/2026
🔥 Socket Firewall is now built into Replit's AI-powered development experience. It’s already blocking 8K malicious packages/day across builders on the platform, giving Replit users stronger protection by default at the moment dependencies are introduced. socket.dev/blog/socket-...
socket.dev
Socket Partners with Replit to Block Malicious Packages in A...
Replit is integrating Socket Firewall into its AI-powered development experience to help protect builders from malicious open source packages.
062
Reposted by Ahmad Nassri
Socket @socket.dev · 09/06/2026
npm accidentally marked a bunch of one-character packages as security holders, including c, i, n, x, several numbers, and even the - package. The registry confirmed it was a tooling bug and said a rollback is underway. socket.dev/blog/npm-too...
socket.dev
npm Tooling Bug Incorrectly Marks One-Character Packages as ...
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.
063
Reposted by Ahmad Nassri
Socket @socket.dev · 21/05/2026
npm nuked every granular access token that bypasses 2FA after another Mini Shai-Hulud wave compromised hundreds of packages. Good news: staged publishing is now in public preview. socket.dev/blog/npm-inv... #NodeJS #JavaScript
socket.dev
npm Invalidates Granular Access Tokens as Mini Shai-Hulud Sw...
npm invalidated all granular access tokens that bypass 2FA after a fresh Mini Shai-Hulud wave compromised 323 npm packages. Staged publishing also ent...
0262
Reposted by Ahmad Nassri
Peter van der Zee @pvdz.ee · 20/05/2026
Socket raised a C round! (Maybe we should be SoCket now! ok eeew no) All I can see on my part is that I've been having an awesome time working on AI and with AI, detection, and what not. Lucky to be part in the right place at the right time :D bsky.app/profile/fero...
092
Reposted by Ahmad Nassri
Feross @feross.bsky.social · 20/05/2026
Today is a big day for @socket.dev. We raised a $60M Series C at a $1B valuation, led by Thrive Capital. 20,000+ orgs, 1.5M repos protected, 1,000+ supply chain attacks blocked per week. 3/5 FAANG companies are customers. We're just getting started.
118514
Ahmad Nassri @ahmadnassri.com · 01/05/2026
4. Exploiting Packagist / GitHub tag mutability 5. Exploits Composer plugins functionality, mimicking npm's "postinstall" (a first!) 6. Audacious trolling on GitHub issues of compromised packages socket.dev/blog/mini-sh...
socket.dev
Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP...
Socket found a malicious Intercom PHP package on Packagist using Composer plugin execution to steal credentials and spread across ecosystems.
010
Ahmad Nassri @ahmadnassri.com · 01/05/2026
Today's "Mini Shai-Hulud" supply chain attack is a wild evolution! 1. Cascading, cross-ecosystem propagation (PyPi ➡️ npmjs ➡️ Packagist) 2. Using a JS runtime (Bun) to infect Python and PHP 3. Impersonates Claude in git commits to hide in plain sight 🧵
110
Reposted by Ahmad Nassri
Socket @socket.dev · 25/04/2026
We’re tracking 73 Open VSX sleeper extensions tied to the GlassWorm campaign, with at least 6 already activated to deliver malware. These cloned extensions initially appear benign, then later become malware delivery vehicles through normal updates. socket.dev/blog/73-open...
socket.dev
73 Open VSX Sleeper Extensions Linked to GlassWorm Show New ...
Socket is tracking cloned Open VSX extensions tied to GlassWorm, with several updated from benign-looking sleepers into malware delivery vehicles.
143
Reposted by Ahmad Nassri
Socket @socket.dev · 22/04/2026
🚨 Breaking: Namastex Labs, the team behind Automagik[.]dev, hit with a supply chain attack affecting its npm packages. The malicious versions replicate TeamPCP-style Canister Worm tradecraft, including secret theft, exfiltration, and self-propagation. socket.dev/blog/namaste...
socket.dev
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm...
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
196
Ahmad Nassri @ahmadnassri.com · 10/04/2026
#opensource #goosonomics #honk socket.dev/blog/dont-ki...
socket.dev
Don't Kill the Goose That Lays the Golden Eggs - Socket
Open source is under attack because of how much value it creates. It has been the foundation of every major software innovation for the last three dec...
030
Ahmad Nassri @ahmadnassri.com · 10/04/2026
🪿 Slaughtering the Goose: Arguing that relying on software you don't control is inherently dangerous, conveniently ignoring that the company relied on that exact unpaid labor to build its initial wealth.
130
Ahmad Nassri @ahmadnassri.com · 10/04/2026
🪿 The Manufactured Reckoning: Dressing up a cynical take as a profound, industry-wide crisis, citing a "collapsing trust model" to create fear around the original open systems.
130
Ahmad Nassri @ahmadnassri.com · 10/04/2026
Key Pillars of Goosonomics: 🪿 Exploiting the Golden Goose: Spending years building profit margins, infrastructure, and products on the backs of free, community-maintained code.
120
Ahmad Nassri @ahmadnassri.com · 10/04/2026
Goosonomics (noun) 🪿 A hypocritical corporate strategy of extracting immense financial value from unpaid, open-source labor, only to later declare OSS "dead" or untrustworthy to justify forking, rebuilding, and rebundling that exact same software as a premium, "safe" product.
1145
Reposted by Ahmad Nassri
Socket @socket.dev · 07/04/2026
"Docker Hardened Images for Node.js, Python, and Rust also include Socket Firewall, which blocks malicious dependencies at install time." Another tool for securing your build pipeline - DHI are free and open source: socket.dev/blog/socket-...
0113
Ahmad Nassri @ahmadnassri.com · 03/04/2026
North Korea is targeting npm maintainers. Not for crypto. For write access to packages downloaded trillions of times a year. Lodash. Fastify. axios. mocha. Node.js core. Even @feross.bsky.social and several @socket.dev engineers! socket.dev/blog/attacke...
socket.dev
Attackers Are Hunting High-Impact Node.js Maintainers in a C...
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
1178
Reposted by Ahmad Nassri
Feross @feross.bsky.social · 02/04/2026
We’re seeing cases where teams can’t explain how they were compromised by the Axios incident because it doesn’t show up in their project's lockfile. The blast radius here is much larger than it looks. Deep dive into the messy reality of modern dependency resolution → socket.dev/blog/hidden-...
socket.dev
The Hidden Blast Radius of the Axios Compromise - Socket
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
01711
Reposted by Ahmad Nassri
Peter van der Zee @pvdz.ee · 01/04/2026
The axios compromise blast radius is much much much bigger than people seem to suspect. The secret: transitive dependencies with open ranges making it extremely obscure and difficult to detect whether you were affected, after the fact.
064
Ahmad Nassri @ahmadnassri.com · 01/04/2026
⚠️ If you're running local mcp servers, you need to do the following: 1. Individually "install" packages you want to use, within a specified directory: (e.g. $HOME/mcp) creating a lockfile 2. Add: "--include-workspace-root --workspace $HOME/mcp --no --offline" to EVERY npx call
293
Ahmad Nassri @ahmadnassri.com · 31/03/2026
📢 ZERO SIGN UP, FREE FOREVER, MALWARE PROTECTION. npm i -g sfw sfw npm install sfw pnpm install sfw yarn install sfw cargo fetch sfw uv pip install socket.dev/blog/introdu...
socket.dev
Introducing Socket Firewall: Free, Proactive Protection for ...
Socket Firewall is a free tool that blocks malicious packages at install time, giving developers proactive protection against rising supply chain atta...
130
Ahmad Nassri @ahmadnassri.com · 31/03/2026
sigh.
010
Ahmad Nassri @ahmadnassri.com · 31/03/2026
🚨 NOT AN EARLY APRIL FOOLS! 🚨 Active supply chain attack on axios@1.14.1. The latest version pulls in plain-crypto-js@4.2.1 -- a brand-new package that didn't exist before today! If you use axios, pin your version and audit your lockfile. Socket's Analysis: socket.dev/blog/axios-n...
socket.dev
Supply Chain Attack on Axios Pulls Malicious Dependency from...
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHu...
011
Reposted by Ahmad Nassri
Socket @socket.dev · 24/03/2026
This is an important situation for every security tool and open source project to monitor right now. cc: @campuscodi.risky.biz @thehackernews.bsky.social @bleepingcomputer.com @techcrunch.com @zackwhittaker.com
011
Ahmad Nassri @ahmadnassri.com · 24/03/2026
These tools are secret + infrastructure + code security scanners by design and used in critical enterprise workflows. If compromised, they risk exposing production environments' secrets with a direct view into where the weak points are. socket.dev/blog/teampcp...
socket.dev
TeamPCP Is Systematically Targeting Security Tools Across th...
TeamPCP is targeting security tools across the OSS ecosystem, turning scanners and CI pipelines into infostealers to access enterprise secrets.
021
Ahmad Nassri @ahmadnassri.com · 24/03/2026
GitHub Actions considered malicious, everybody move back to Jenkin! 🙈 "GitHub’s architecture makes fork commits reachable by SHA from the parent repo" 🚨 amazing breakdown by Rose Security 👏 rosesecurity.dev/2026/03/20/t... #trivy #github #actions #sca #supplychain #security
010
Ahmad Nassri @ahmadnassri.com · 22/03/2026
Repos contain full git history going back six years and likely all their proprietary source code. Repo names include controller, aqua-react, services, aqua-deployer, ops-manager, tracee-detectors, and internal knowledge bases.
000
Ahmad Nassri @ahmadnassri.com · 22/03/2026
🚨 AquaSecurity's private source code seems to be fully compromised and in the open, released by the attackers today to github.com/aquasec-com The leak includes private keys credential scripts in the exposed repos. All repos have description: "TeamPCP Owns Aqua Security."
110
Reposted by Ahmad Nassri
Socket @socket.dev · 19/03/2026
In less than 6 months, companies shipping software in Europe face the first Cyber Resilience Act deadline. ENISA's latest advisory on secure package manager use spells out expectations for SBOMs, dependency monitoring, and vulnerability reporting. socket.dev/blog/enisa-t...
socket.dev
ENISA Publishes Technical Advisory on Secure Use of Package ...
ENISA’s new package manager advisory outlines the dependency security practices companies will need to demonstrate as the EU’s Cyber Resilience Act be...
043
Ahmad Nassri @ahmadnassri.com · 16/03/2026
⚠️ UPDATE: we're now tracking 213+ affected package artifacts across this campaign! socket.dev/supply-chain...
socket.dev
GlassWorm v2 - Socket
Socket fights vulnerabilities and provides visibility, defense-in-depth, and proactive supply chain protection for JavaScript, Python, and Go dependencies.
020
Ahmad Nassri @ahmadnassri.com · 16/03/2026
🚨 VSCode & OpenVSX users, take note: The "GlassWorm" campaign has evolved to weaponize the very structure of your IDE Extensions. The @socket.dev Research Team just uncovered over 73 new malicious OpenVSX extensions. Read the full technical breakdown + IOCs on our blog socket.dev/blog/open-vs...
socket.dev
72 Malicious Open VSX Extensions Linked to GlassWorm Campaig...
Since January 31, 2026, we identified at least 72 additional malicious Open VSX extensions, including transitive GlassWorm loader extensions targeting...
000
Ahmad Nassri @ahmadnassri.com · 20/02/2026
Join Socket + Cloudflare in a livestream NOW discussing #SANDWORM_MODE the Shai-Hulud-Style npm Worm Hijacking CI Workflows and Poisoning AI Toolchains www.youtube.com/watch?v=OQ6w...
youtube.com
🚨 Active Shai-Hulud–Like npm Supply Chain Attack: SANDWORM_MODE
YouTube video by Socket Security
010
Ahmad Nassri @ahmadnassri.com · 20/02/2026
Join @socket.dev + @cloudflare.social in a livestream NOW discussing #SANDWORM_MODE the Shai-Hulud-Style npm Worm Hijacking CI Workflows and Poisoning AI Toolchains www.youtube.com/watch?v=OQ6w...
youtube.com
🚨 Active Shai-Hulud–Like npm Supply Chain Attack: SANDWORM_MODE
YouTube video by Socket Security
030
Ahmad Nassri @ahmadnassri.com · 20/02/2026
If you think your organization may have been affected or would like help assessing your exposure, please reach out and we will help.
010
Ahmad Nassri @ahmadnassri.com · 20/02/2026
If you are a @socket.dev customer, these packages are automatically blocked in the environments where Socket is deployed (and have been blocked since our initial confirmation ~36 hours ago).
120
Ahmad Nassri @ahmadnassri.com · 20/02/2026
The campaign is designed to steal credentials from developer workstations and CI environments, inject malicious GitHub Actions workflows for self-propagation, poison AI toolchains via rogue MCP servers, and exfiltrate LLM API keys.
100
Ahmad Nassri @ahmadnassri.com · 20/02/2026
The @socket.dev team caught super early signals of this attack campaign leading to preemptive shutdown! proud of the team and our advanced threat detection engine! 💪 Thankful for the rapid response and takedown @npmjs.bsky.social @github.com @cloudflare.social 🙏 #shaihulud #SANDWORM_MODE
2124
Reposted by Ahmad Nassri
Feross @feross.bsky.social · 20/02/2026
Incoming news. Stay tuned.
131
Reposted by Ahmad Nassri
Socket @socket.dev · 19/02/2026
Really cool to see @npmjs.bsky.social featuring more security information on package pages, including a link to Socket's analysis! 🤩 Here's what you'll find when you click through → socket.dev/blog/socket-... #NodeJS #JavaScript
094
Reposted by Ahmad Nassri
Socket @socket.dev · 13/02/2026
New Research: Malicious Chrome extension targets Meta Business Suite/Facebook Business Manager, steals TOTP 2FA seeds + codes, and exfiltrates Business Manager exports (People + analytics). Full analysis: socket.dev/blog/malicio...
socket.dev
Malicious Chrome Extension Steals Meta Business Manager Expo...
Chrome extension CL Suite by @CLMasters neutralizes 2FA for Facebook and Meta Business accounts while exfiltrating Business Manager contact and analyt...
022
Reposted by Ahmad Nassri
Socket @socket.dev · 21/01/2026
🚀 Socket Launch Week Day 3: We’re launching supply chain attack campaign tracking in the Socket dashboard!
131
Reposted by Ahmad Nassri
Socket @socket.dev · 24/12/2025
Add this episode to your podcast listening queue during the holidays. 🎧 Socket CTO @ahmadnassri.com talks through practical AI coding workflows, where AI actually helps teams today, and why the biggest shifts are being driven by economics. socket.dev/blog/enginee...
022