Sign in

Philipp Burckhardt

@burckhap.bsky.social
69 followers 116 following 56 posts

⚡Securing Software Supply Chains @SocketSecurity (socket.dev) 🔭 Scientific computing for the web via @stdlibjs (stdlib.io)

PostsRepliesMedia
Philipp Burckhardt @burckhap.bsky.social · 22/04/2026
Today, Socket detected malicious Namastex.ai npm packages that appear to replicate TeamPCP-style Canister Worm patterns, including exfiltration and self-propagation. More on our blog, including actions for defenders to take against yet another supply chain attack on the npm open-source ecosystem.
socket.dev
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm...
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
010
Philipp Burckhardt @burckhap.bsky.social · 14/03/2026
We identified 72 malicious Open VSX extensions linked to the GlassWorm campaign, including many cases where the malware is distributed transitively by being delilvered via covert extension packs. See below for link to our full coverage.
010
Reposted by Philipp Burckhardt
Socket @socket.dev · 23/12/2025
🚨 New research: A spearphishing campaign published 27 malicious npm packages that host browser-run lures mimicking document portals and Microsoft sign-in to steal credentials. This operation targets manufacturing and healthcare orgs in the U.S. and allied countries. socket.dev/blog/spearph...
socket.dev
Spearphishing Campaign Abuses npm Registry to Target U.S. an...
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, ta...
063
Philipp Burckhardt @burckhap.bsky.social · 26/09/2025
While we haven't seen major supply chain attacks hitting any of the major open-source ecosystems, the Socket Threat Research Team uncovered some fascinating and creative attack techniques worth sharing:
pypi-mirror.org
121
Philipp Burckhardt @burckhap.bsky.social · 17/07/2025
Published my take on METR's surprising study that I participated in: AI tools made experienced developers 19% slower (expectation was that they would become 40% faster with AI!)🤯 I dive into the why, where AI coding tools actually help, and how I've shifted from handholding AI to async delegation.
100
Philipp Burckhardt @burckhap.bsky.social · 16/07/2025
Two major npm supply chain discoveries this week from the Socket Research Team highlight a critical gap in traditional security approaches. Both threats would slip past security tools that rely on vulnerability databases or metadata alone.
100
Philipp Burckhardt @burckhap.bsky.social · 08/05/2025
Over the last few months, I have been picking up Cursor again after finding it not substantially improving my productivity when I tried it last year. It, and the LLMs powering AI code completions, have gotten so much better that I now really enjoy its agent workflow.
120
Philipp Burckhardt @burckhap.bsky.social · 01/05/2025
Our team at Socket has uncovered a Go module supply chain attack that deploys destructive disk-erasing payloads. A single code line triggers a shell script that overwrites disks, making data irretrievable. The attack leverages Go's open ecosystem, exploiting namespace confusion.
socket.dev
wget to Wipeout: Malicious Go Modules Fetch Destructive Payl...
Socket's research uncovers three dangerous Go modules that contain obfuscated disk-wiping malware, threatening complete data loss.
120
Philipp Burckhardt @burckhap.bsky.social · 30/04/2025
The Socket research team discovered seven "Coffin-Codes" packages that leveraged Gmail's SMTP protocol to create covert channels for extracting data and executing commands.
socket.dev
Using Trusted Protocols Against You: Gmail as a C2 Mechanism...
Socket uncovers malicious packages on PyPI using Gmail's SMTP protocol for command and control (C2) to exfiltrate data and execute commands.
110
Philipp Burckhardt @burckhap.bsky.social · 23/04/2025
🚨SECURITY ALERT: Uncovering "The Bad Seeds" in Package Registries 🚨 Socket researchers have identified three malicious npm and PyPI packages that, like their namesake, are doing the devil's work - harvesting crypto wallet credentials while posing as innocent developer tools.
100
Philipp Burckhardt @burckhap.bsky.social · 20/04/2025
Last week, Socket researchers have discovered malicious npm packages deploying backdoors through fake Telegram bot libraries and payment integrations - details in thread below.
socket.dev
Malicious npm Package Disguised as Advcash Integration Trigg...
The Socket Research Team investigates a malicious npm package that appears to be an Advcash integration but triggers a reverse shell during payment su...
201
Reposted by Philipp Burckhardt
Daniel Rosenwasser @danr.bsky.social · 11/03/2025
This is tremendous for TypeScript and JavaScript developers everywhere. We're building a new TypeScript that runs lighter, goes faster, and scales well on enormous codebases. This was a big decision and a lot of work, but we are seeing promising results for this new foundation!
5484
Philipp Burckhardt @burckhap.bsky.social · 26/02/2025
Eleven years ago, Athan Reines and I set out to bring numerical and statistical computing to the web, which culminated in the creation of stdlib. What started as an ambitious idea has grown into a thriving open-source project which has truly taken off since being accepted into GSoC last year.
130
Philipp Burckhardt @burckhap.bsky.social · 26/02/2025
🚨 New research from the Socket threat analysis team! 🚨 We've uncovered a harmful PyPI package exploiting the Deezer API for systematic music piracy. Learn more about the detection of this exploit and its implications for developers and users alike: buff.ly/3D9CHjW
socket.dev
Malicious PyPI Package Exploits Deezer API for Coordinated M...
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server contr...
111
Philipp Burckhardt @burckhap.bsky.social · 04/02/2025
We uncovered a stealthy Go supply chain attack: a malicious BoltDB typosquat backdoored dev machines while looking clean on GitHub!
socket.dev
Go Supply Chain Attack: Malicious Package Exploits Go Module...
Socket researchers uncovered a backdoored typosquat of BoltDB in the Go ecosystem, exploiting Go Module Proxy caching to persist undetected for years.
110
Philipp Burckhardt @burckhap.bsky.social · 31/01/2025
🚨 North Korean APT Lazarus is targeting developers with a malicious npm package! The postcss-optimizer package delivers BeaverTail malware, stealing credentials & deploying second-stage payloads. Read the full analysis on the Socket blog:
buff.ly
North Korean APT Lazarus Targets Developers with Malicious n...
Malicious npm package postcss-optimizer delivers BeaverTail malware, targeting developer systems; similarities to past campaigns suggest a North Korea...
011
Philipp Burckhardt @burckhap.bsky.social · 14/01/2025
New on the Socket Blog: Kush Pandya uncovered a hidden kill switch in npm packages targeting two popular libraries, chalk and chokidar. This is a deep dive into a recent typo-squatting attack, illustrating how malicious packages can jeopardize your software supply chain.
buff.ly
Kill Switch Hidden in npm Packages Typosquatting Chalk and C...
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data the...
031
Philipp Burckhardt @burckhap.bsky.social · 04/01/2025
2024 was transformational for stdlib and our mission to build the fundamental numerical library for the web. Huge thanks to the dozens of new contributors who helped make it possible! Read Athan Reines' retrospective here: buff.ly/4j6dIht Wishing everyone a great 2025!
buff.ly
2024 Retrospective
A look back at 2024 and a preview of the year ahead for all things stdlib.
010
Philipp Burckhardt @burckhap.bsky.social · 17/12/2024
Last week, we discovered a harmful npm package that pretends to be a video downloader. However, it secretly collected credentials and data by logging web form inputs, metadata, cookies, and passwords, sending them via Telegram and Discord webhooks.
110
Philipp Burckhardt @burckhap.bsky.social · 07/12/2024
Our threat research team recently discovered a malicious Maven package impersonating “XZ for Java”. As you may remember, the widely depended on XZ Utils compression library fell prey to a sophisticated social engineering attack, which allowed an attacker to sneak in malicious code earlier this year.
100
Philipp Burckhardt @burckhap.bsky.social · 03/12/2024
We detected a malicious npm package, solana-systemprogram-utils, targeting the funds of Solana developers. The package reroutes 2% of transactions to an attacker's hardcoded address. Always audit your libraries and rely on trusted sources.
100
Philipp Burckhardt @burckhap.bsky.social · 01/12/2024
Open source maintainers getting funding directly for security? Yes, please. With LLMs pumping out more code than ever, putting security first in OSS isn’t optional. Awesome to see the recently announced GitHub Secure Open Source Fund, established by GitHub together with >12 partner institutions.
100
Philipp Burckhardt @burckhap.bsky.social · 30/11/2024
At the start of this week, Anthropic released the Model Context Protocol (MCP), an open standard for connecting AI assistants to data sources like databases, content repositories, and dev environments. It's aiming to solve a key challenge: giving AI models access to real-world data.
120
Philipp Burckhardt @burckhap.bsky.social · 27/11/2024
Interesting findings about "ghost engineers", but they invite some skepticism. Measuring developer productivity is notoriously challenging—commit counts and hours logged rarely capture true impact.
100