Sign in

Philipp Burckhardt

@burckhap.bsky.social
69 followers 116 following 56 posts

⚡Securing Software Supply Chains @SocketSecurity (socket.dev) 🔭 Scientific computing for the web via @stdlibjs (stdlib.io)

PostsRepliesMedia
Philipp Burckhardt @burckhap.bsky.social · 22/04/2026
Today, Socket detected malicious Namastex.ai npm packages that appear to replicate TeamPCP-style Canister Worm patterns, including exfiltration and self-propagation. More on our blog, including actions for defenders to take against yet another supply chain attack on the npm open-source ecosystem.
socket.dev
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm...
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
010
Philipp Burckhardt @burckhap.bsky.social · 14/03/2026
We identified 72 malicious Open VSX extensions linked to the GlassWorm campaign, including many cases where the malware is distributed transitively by being delilvered via covert extension packs. See below for link to our full coverage.
010
Reposted by Philipp Burckhardt
Socket @socket.dev · 23/12/2025
🚨 New research: A spearphishing campaign published 27 malicious npm packages that host browser-run lures mimicking document portals and Microsoft sign-in to steal credentials. This operation targets manufacturing and healthcare orgs in the U.S. and allied countries. socket.dev/blog/spearph...
socket.dev
Spearphishing Campaign Abuses npm Registry to Target U.S. an...
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, ta...
063
Philipp Burckhardt @burckhap.bsky.social · 26/09/2025
Read more on our blog: socket.dev/blog/malicio... and socket.dev/blog/two-mal...
socket.dev
Malicious fezbox npm Package Steals Browser Passwords from C...
A malicious package uses a QR code as steganography in an innovative technique.
010
Philipp Burckhardt @burckhap.bsky.social · 26/09/2025
Given an ongoing PyPI phishing campaign that continues to target users with new domains through legitimate-looking emails requesting "email verification" that actually steal credentials, we are on the lookout for any compromised packages in the PyPI ecosystem specifically.
100
Philipp Burckhardt @burckhap.bsky.social · 26/09/2025
Two malicious Rust crates (faster_log and async_println) impersonated the popular fast_log library to steal Solana and Ethereum wallet keys from source code. Downloaded 8,424 times before removal, these packages scanned developer files for private keys and exfiltrated them to a C2 server.
crates.io
110
Philipp Burckhardt @burckhap.bsky.social · 26/09/2025
QR Code Steganography in npm: We discovered fezbox, a malicious npm package using an innovative steganographic technique for obfuscation - hiding malware inside a QR code! The package fetches a QR code from a remote URL and executes code hidden within it to steal browser credentials.
110
Philipp Burckhardt @burckhap.bsky.social · 26/09/2025
While we haven't seen major supply chain attacks hitting any of the major open-source ecosystems, the Socket Threat Research Team uncovered some fascinating and creative attack techniques worth sharing:
pypi-mirror.org
121
Philipp Burckhardt @burckhap.bsky.social · 17/07/2025
Read the full blog post here: blog.stdlib.io/reflection-o...
blog.stdlib.io
Using AI in the development of stdlib
A reflection on stdlib's participation in the 2025 METR study on AI's impact on open-source developer productivity.
062
Philipp Burckhardt @burckhap.bsky.social · 17/07/2025
Published my take on METR's surprising study that I participated in: AI tools made experienced developers 19% slower (expectation was that they would become 40% faster with AI!)🤯 I dive into the why, where AI coding tools actually help, and how I've shifted from handholding AI to async delegation.
100
Philipp Burckhardt @burckhap.bsky.social · 16/07/2025
We found hidden functionality in 28+ npm packages that disables UI for Russian-language users visiting .ru or .by domains. No CVEs. No advisories. No documentation. Just behavior-based disruption quietly copied into packages and shipped to production. Read more: socket.dev/blog/protest...
socket.dev
Tracking Protestware Spread: 28 npm Packages Affected by Pay...
Undocumented protestware found in 28 npm packages disrupts UI for Russian-language users visiting Russian and Belarusian domains.
000
Philipp Burckhardt @burckhap.bsky.social · 16/07/2025
The latest North Korean "Contagious Interview" wave includes 67 new malicious packages with a previously unknown malware loader, accumulating over 17,000 downloads. Read more on out blog: socket.dev/blog/contagi...
100
Philipp Burckhardt @burckhap.bsky.social · 16/07/2025
Two major npm supply chain discoveries this week from the Socket Research Team highlight a critical gap in traditional security approaches. Both threats would slip past security tools that rely on vulnerability databases or metadata alone.
100
Philipp Burckhardt @burckhap.bsky.social · 08/05/2025
These packages, disguised as "the cheapest Cursor API," install backdoors that steal credentials and modify crucial files. sw-cur, sw-cur1, and aiide-cur have been downloaded 3,200+ times before discovery. Read about them on the Socket blog: socket.dev/blog/malicio...
socket.dev
Backdooring the IDE: Malicious npm Packages Hijack Cursor Ed...
Malicious npm packages posing as developer tools target macOS Cursor IDE users, stealing credentials and modifying files to gain persistent backdoor a...
000
Philipp Burckhardt @burckhap.bsky.social · 08/05/2025
🚨 With vibe coding being on everyone's minds and AI code generations seemingly becoming ubiquitous, it is not surprising that this attracts also malicious actors. Kirill Boychenko uncovered three malicious npm packages targeting Cursor users on macOS.
110
Philipp Burckhardt @burckhap.bsky.social · 08/05/2025
Over the last few months, I have been picking up Cursor again after finding it not substantially improving my productivity when I tried it last year. It, and the LLMs powering AI code completions, have gotten so much better that I now really enjoy its agent workflow.
120
Philipp Burckhardt @burckhap.bsky.social · 01/05/2025
The attack was comprised of three malicious modules with hidden destructive code, using array-based string obfuscation and dynamic payload execution, targeting Linux servers and dev environments. Check our full technical analysis and protection tips: socket.dev/blog/wget-to... #CyberSecurity
socket.dev
wget to Wipeout: Malicious Go Modules Fetch Destructive Payl...
Socket's research uncovers three dangerous Go modules that contain obfuscated disk-wiping malware, threatening complete data loss.
000
Philipp Burckhardt @burckhap.bsky.social · 01/05/2025
Our team at Socket has uncovered a Go module supply chain attack that deploys destructive disk-erasing payloads. A single code line triggers a shell script that overwrites disks, making data irretrievable. The attack leverages Go's open ecosystem, exploiting namespace confusion.
socket.dev
wget to Wipeout: Malicious Go Modules Fetch Destructive Payl...
Socket's research uncovers three dangerous Go modules that contain obfuscated disk-wiping malware, threatening complete data loss.
120
Philipp Burckhardt @burckhap.bsky.social · 30/04/2025
The threat actor started publishing these packages in 2021, consistently employing comparable strategies while remaining undetected. Full technical analysis here: socket.dev/blog/using-t...
socket.dev
Using Trusted Protocols Against You: Gmail as a C2 Mechanism...
Socket uncovers malicious packages on PyPI using Gmail's SMTP protocol for command and control (C2) to exfiltrate data and execute commands.
000
Philipp Burckhardt @burckhap.bsky.social · 30/04/2025
These packages use embedded credentials to connect to Gmail's SMTP server, relay signals to emails under the control of attackers, and initiate WebSocket connections that can bypass firewalls since the connection starts from within the network.
socket.dev
Using Trusted Protocols Against You: Gmail as a C2 Mechanism...
Socket uncovers malicious packages on PyPI using Gmail's SMTP protocol for command and control (C2) to exfiltrate data and execute commands.
100
Philipp Burckhardt @burckhap.bsky.social · 30/04/2025
The Socket research team discovered seven "Coffin-Codes" packages that leveraged Gmail's SMTP protocol to create covert channels for extracting data and executing commands.
socket.dev
Using Trusted Protocols Against You: Gmail as a C2 Mechanism...
Socket uncovers malicious packages on PyPI using Gmail's SMTP protocol for command and control (C2) to exfiltrate data and execute commands.
110
Philipp Burckhardt @burckhap.bsky.social · 23/04/2025
Remember: If any code asks for your seed phrase, there's no salvation - it's not a feature, it's a scam. Here's the complete write-up: socket.dev/blog/malicio...
socket.dev
The Bad Seeds: Malicious npm and PyPI Packages Pose as Devel...
Socket researchers uncovered malicious npm and PyPI packages that steal crypto wallet credentials using Google Analytics and Telegram for exfiltration...
000
Philipp Burckhardt @burckhap.bsky.social · 23/04/2025
With over 8,000 combined downloads, these digital highwaymen use Google Analytics and Telegram for exfiltration - truly where the wild roses grow. While Socket is celebrating our launch week and Coana acquisition, the bad actors never take a break.
100
Philipp Burckhardt @burckhap.bsky.social · 23/04/2025
🚨SECURITY ALERT: Uncovering "The Bad Seeds" in Package Registries 🚨 Socket researchers have identified three malicious npm and PyPI packages that, like their namesake, are doing the devil's work - harvesting crypto wallet credentials while posing as innocent developer tools.
100
Philipp Burckhardt @burckhap.bsky.social · 20/04/2025
What makes these attacks concerning is that they target business-critical workflows use sophisticated disguises that implement legitimate functionality execute at specific runtime events, not installation The malicious packages have been reported and are meanwhile removed from the npm registry.
000
Philipp Burckhardt @burckhap.bsky.social · 20/04/2025
The second attack involves an npm package disguised as an Advcash payment integration that triggers a reverse shell during payment success callbacks, allowing attackers to gain control of servers processing transactions. Read more about it here: socket.dev/blog/npm-pac...
socket.dev
Malicious npm Package Disguised as Advcash Integration Trigg...
The Socket Research Team investigates a malicious npm package that appears to be an Advcash integration but triggers a reverse shell during payment su...
100
Philipp Burckhardt @burckhap.bsky.social · 20/04/2025
Read the full analysis on the Socket blog: socket.dev/blog/npm-mal...
socket.dev
npm Malware Targets Telegram Bot Developers with Persistent ...
Malicious npm packages posing as Telegram bot libraries install SSH backdoors and exfiltrate data from Linux developer machines.
100
Philipp Burckhardt @burckhap.bsky.social · 20/04/2025
The first attack targets Telegram bot developers with typosquatted packages (node-telegram-utils, node-telegram-bots-api, node-telegram-util) that install persistent SSH backdoors on Linux machines, masquerading as the legitimate node-telegram-bot-api library (4.17M+ downloads).
100
Philipp Burckhardt @burckhap.bsky.social · 20/04/2025
Last week, Socket researchers have discovered malicious npm packages deploying backdoors through fake Telegram bot libraries and payment integrations - details in thread below.
socket.dev
Malicious npm Package Disguised as Advcash Integration Trigg...
The Socket Research Team investigates a malicious npm package that appears to be an Advcash integration but triggers a reverse shell during payment su...
201
Reposted by Philipp Burckhardt
Daniel Rosenwasser @danr.bsky.social · 11/03/2025
This is tremendous for TypeScript and JavaScript developers everywhere. We're building a new TypeScript that runs lighter, goes faster, and scales well on enormous codebases. This was a big decision and a lot of work, but we are seeing promising results for this new foundation!
5484
Philipp Burckhardt @burckhap.bsky.social · 28/02/2025
If you go to the GitHub repository for any of these packages, you will see a `tea.yml` file, a file associated with the decentralized tea.xyz protocol to reward open-source contributions with crypto tokens. We previously reported on similar spam campaigns: socket.dev/blog/massive...
socket.dev
Massive Automated Spam Campaign Abuses GitHub to Flood npm R...
In a reprisal of their previous Tea[.]xyz spam campaign, a new wave of thousands of garbage packages are hitting npm, to artificially inflate the numb...
150
Philipp Burckhardt @burckhap.bsky.social · 26/02/2025
If you’re interested in open source, numerical computing, or just love hearing about non-traditional paths into software, this episode is a must-listen. 🎧 Check it out here: buff.ly/4bk7ojd Huge thanks to our incredible contributor community! Would love to hear your thoughts! 🚀💡
buff.ly
Exploring stdlib: JavaScript's Answer to Technical Computing - Inspiring Computing
This episode of Inspiring Computing features a discussion with Athan, the maintainer of stdlib, a JavaScript library designed for numerical and scientific computing. Athan shares his experience and…
000
Philipp Burckhardt @burckhap.bsky.social · 26/02/2025
In this episode, he talks about: 🔹 The unconventional path from science to software engineering 🔹 The challenges (and rewards!) of building stdlib 🔹 Why JavaScript is more powerful for numerical computing than many think 🔹 The future of scientific computing on the web
110
Philipp Burckhardt @burckhap.bsky.social · 26/02/2025
Athan recently joined Gareth Thomas on the Inspiring Computing podcast to share his journey—how he went from wet lab biophysics experiments to leading an open-source project, championing JavaScript for numerical computing, and eventually landing at Quansight.
100
Philipp Burckhardt @burckhap.bsky.social · 26/02/2025
Eleven years ago, Athan Reines and I set out to bring numerical and statistical computing to the web, which culminated in the creation of stdlib. What started as an ambitious idea has grown into a thriving open-source project which has truly taken off since being accepted into GSoC last year.
130
Philipp Burckhardt @burckhap.bsky.social · 26/02/2025
This follows an earlier finding published this week about a malicious npm package designed to steal cryptocurrency wallet keys from TON Wallet users. buff.ly/43dE7o5 Stay vigilant, and let’s keep open-source secure!
buff.ly
TON Wallet Security Threat: Malicious npm Package Steals Cry...
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in th...
000
Philipp Burckhardt @burckhap.bsky.social · 26/02/2025
🚨 New research from the Socket threat analysis team! 🚨 We've uncovered a harmful PyPI package exploiting the Deezer API for systematic music piracy. Learn more about the detection of this exploit and its implications for developers and users alike: buff.ly/3D9CHjW
socket.dev
Malicious PyPI Package Exploits Deezer API for Coordinated M...
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server contr...
111
Philipp Burckhardt @burckhap.bsky.social · 21/02/2025
There might not be even one in this specific interaction. Recently learned that spammers and scammers may initiate conversations to "warm up" numbers and make them appear legitimate in the eyes of the carriers. Having "normal" conversatios with a back and forth helps evade spam detection.
000
Philipp Burckhardt @burckhap.bsky.social · 04/02/2025
Read about it on the Socket blog: buff.ly/3Q1LEi4
buff.ly
Go Supply Chain Attack: Malicious Package Exploits Go Module...
Socket researchers uncovered a backdoored typosquat of BoltDB in the Go ecosystem, exploiting Go Module Proxy caching to persist undetected for years.
000
Philipp Burckhardt @burckhap.bsky.social · 04/02/2025
How it worked: - A malicious package was permanently cached by the Go Module Proxy - The attacker rewrote the GitHub tag after caching, erasing all traces of malware from GitHub Developers using `go get` unknowingly installed the backdoored version. This persistence trick went undetected for years.
100
Philipp Burckhardt @burckhap.bsky.social · 04/02/2025
We uncovered a stealthy Go supply chain attack: a malicious BoltDB typosquat backdoored dev machines while looking clean on GitHub!
socket.dev
Go Supply Chain Attack: Malicious Package Exploits Go Module...
Socket researchers uncovered a backdoored typosquat of BoltDB in the Go ecosystem, exploiting Go Module Proxy caching to persist undetected for years.
110
Philipp Burckhardt @burckhap.bsky.social · 31/01/2025
🚨 North Korean APT Lazarus is targeting developers with a malicious npm package! The postcss-optimizer package delivers BeaverTail malware, stealing credentials & deploying second-stage payloads. Read the full analysis on the Socket blog:
buff.ly
North Korean APT Lazarus Targets Developers with Malicious n...
Malicious npm package postcss-optimizer delivers BeaverTail malware, targeting developer systems; similarities to past campaigns suggest a North Korea...
011
Philipp Burckhardt @burckhap.bsky.social · 14/01/2025
New on the Socket Blog: Kush Pandya uncovered a hidden kill switch in npm packages targeting two popular libraries, chalk and chokidar. This is a deep dive into a recent typo-squatting attack, illustrating how malicious packages can jeopardize your software supply chain.
buff.ly
Kill Switch Hidden in npm Packages Typosquatting Chalk and C...
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data the...
031
Philipp Burckhardt @burckhap.bsky.social · 11/01/2025
One of his best. Need to rewatch it.
000
Philipp Burckhardt @burckhap.bsky.social · 11/01/2025
Even assuming the tech makes continued progress, I have observed that people often underestimate inertia in organizations and society at large. Your predictions seem plausible und level-headed to me; guess we will see how it all shakes out!
010
Philipp Burckhardt @burckhap.bsky.social · 04/01/2025
2024 was transformational for stdlib and our mission to build the fundamental numerical library for the web. Huge thanks to the dozens of new contributors who helped make it possible! Read Athan Reines' retrospective here: buff.ly/4j6dIht Wishing everyone a great 2025!
buff.ly
2024 Retrospective
A look back at 2024 and a preview of the year ahead for all things stdlib.
010
Philipp Burckhardt @burckhap.bsky.social · 17/12/2024
Prefer using official SDKs for interacting with APIs and consider using Socket's free tools to protect your software supply chain. Learn more about this finding on our blog: buff.ly/4fqQSOF
buff.ly
Data Theft Repackaged: A Case Study in Malicious Wrapper Pac...
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
000
Philipp Burckhardt @burckhap.bsky.social · 17/12/2024
Last week, we discovered a harmful npm package that pretends to be a video downloader. However, it secretly collected credentials and data by logging web form inputs, metadata, cookies, and passwords, sending them via Telegram and Discord webhooks.
110
Philipp Burckhardt @burckhap.bsky.social · 07/12/2024
In this new case, a threat actor published a malicious version of the XZ Java package, with the intent to fool developers in confusing it with the legitimate package. What the attacks have in common is relying on human trust as much as technical exploits. Learn more here: buff.ly/3ZKbCMU
buff.ly
Malicious Maven Package Impersonating 'XZ for Java' Library ...
Socket researchers found a malicious Maven package impersonating the legitimate ‘XZ for Java’ library, introducing a backdoor for remote code executio...
000
Philipp Burckhardt @burckhap.bsky.social · 07/12/2024
Our threat research team recently discovered a malicious Maven package impersonating “XZ for Java”. As you may remember, the widely depended on XZ Utils compression library fell prey to a sophisticated social engineering attack, which allowed an attacker to sneak in malicious code earlier this year.
100