Reposted by Ferossboredchilada @cyfar.ca · 02/10/2026@socket.dev Malicious themes across VS Code and Open VSX delivered loaders linked to GlassWorm. - IOCs: fingercakes4sale[.]store, 173[.]232[.]146[.]211, BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC - #GlassWorm #Malware #ThreatIntelsocket.devGlassWorm VS Code Theme Loaders 011
Feross @feross.bsky.social · 01/10/2026Capital One operates in one of the most demanding security environments in the world. As AI accelerates how software gets built, evaluating dependencies in the pipeline is non-negotiable. Excited to share how they’re using Socket for proactive supply chain security: socket.dev/blog/capital...socket.devSecuring the Financial Frontier: How Capital One Uses Socket for Open Source SecurityCapital One is partnering with Socket to proactively secure its open source supply chain. 011
Feross @feross.bsky.social · 29/09/2026Proud that @socket.dev is protecting America's software supply chain, whether the code is written by humans or AI. 031
Feross @feross.bsky.social · 29/09/2026AI coding agents are writing code faster than ever and pulling in more open source dependencies than ever. @socket.dev is the guardrail that lets developers and agents move fast without shipping malicious or high-risk components. 130
Feross @feross.bsky.social · 29/09/2026Socket now protects four of the Magnificent Seven, two of the three hyperscalers, nearly every leading AI lab, and one of America's largest automakers. This summer, @socket.dev automatically blocked two live supply chain attacks at the world's largest company. 151
Reposted by FerossSocket @socket.dev · 24/09/2026🚨 Two GitHub Actions compromised in May’s Mini Shai-Hulud campaign are running malware again. The repositories were re-enabled with malicious release tags intact, putting thousands of downstream repositories at risk. socket.dev/blog/mini-sh...socket.devRe-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-HuludTwo compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud. 173
Reposted by FerossSocket @socket.dev · 26/09/2026Open source’s next chapter might be a thousand slightly different versions of the same software. socket.dev/blog/oj-vite... 162
Reposted by FerossSocket @socket.dev · 25/09/2026Maintainers spend countless hours keeping the open source projects we all rely on secure. Too often, that work is unpaid. Socket is proud to join @openjsf.org's new Security Stewardship Program to help fund the researchers and maintainers protecting Node.js. socket.dev/blog/openjs-...socket.devSocket Joins New OpenJS Program to Fund Node.js Security WorkSocket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases. 0248
Reposted by Ferossboredchilada @cyfar.ca · 24/09/2026@socket.dev Fake PDF verifier steals Google session cookies and can reset passwords. - IOCs: pdf[.]gusercontent[.]com, pdf[.]gusercontent[.]com/api/accounts/collect/, pdf-para-texto@extensao[.]local - #AccountTakeover #Malware #ThreatIntelsocket.devMalicious Firefox Extension Hijacks Google Accounts 011
Feross @feross.bsky.social · 22/09/2026Two npm token changes coming: 1. Tokens that bypass 2FA are losing power (no more changing maintainers/org membership). 2. ~Jan 2027: staged publishing, where a human with 2FA approves the actual ship. Details: risky.biz/RBNEWSSI140/ 021
Reposted by FerossNodeConf.eu @nodeconf.eu · 21/09/2026Mikola is a Principal Software Engineer at @socket.dev, where his work focuses on software supply chain security: detecting malicious packages and fixing vulnerable ones. 111
Reposted by FerossNodeConf.eu @nodeconf.eu · 21/09/2026🥁 𝐒𝐩𝐞𝐚𝐤𝐞𝐫 𝐀𝐧𝐧𝐨𝐮𝐧𝐜𝐞𝐦𝐞𝐧𝐭🎙️ Thrilled to have @mikolalysenko.bsky.social on the #NodeConfEU 2026 stage! He'll tell us the story of "𝐃𝐞𝐥𝐞𝐭𝐞 𝐚𝐥𝐥 𝐂𝐕𝐄𝐬." 🎟️Don't miss it out; secure your tickets www.nodeconf.eu 186
Feross @feross.bsky.social · 21/09/2026The wildest part of a recent npm attack was the command-and-control: it ran over libp2p, the BitTorrent DHT, IPFS, Ethereum smart contracts, and Nostr relays. Every decentralization protocol, as C2: risky.biz/RBNEWSSI140/ 161
Feross @feross.bsky.social · 18/09/2026npm 12 silently skips install scripts, including legit ones that compile native modules. The result: prod failures, then teams blanket-allowing everything to make CI green. Flip the soft-fail into a hard-fail instead: risky.biz/RBNEWSSI140/ 000
Reposted by Ferossboredchilada @cyfar.ca · 17/09/2026@socket.dev PolinRider compromised nova-two-factor dev branches via GitHub accounts, targeting developer environments. - IOCs: PolinRider, visanduma/nova-two-factor@dev-main - #Malware #SupplyChain #ThreatIntelsocket.devPolinRider Hits Packagist 012
Feross @feross.bsky.social · 17/09/2026Signatures and provenance are useful, but they don't answer the real question: What does this code actually do when you run it? What does it touch? What does it connect to? That's the source of truth: risky.biz/RBNEWSSI140/ 010
Reposted by FerossJerod Santo @jerod.bsky.social · 14/09/2026So excited to join @feross.bsky.social and this amazing team. Wrote more about it on my site 👇 jerodsanto.net/2026/09/join...jerodsanto.netI'm joining Socket!When I said goodbye to The Changelog in March, people asked me about this bit: Part of me wants to go get a software engineering job. Part of me wants to keep creating content. Part of me wants to … 041
Reposted by FerossJerod Santo @jerod.bsky.social · 16/09/2026As I made my way through @socket.dev's onboarding materials, I was pleasantly surprised to see Ken Thompson’s "Reflections on Trusting Trust" in the list of required reading. I pulled a few quotes and jotted down notes as I went: jerodsanto.net/2026/09/refl...jerodsanto.netReflections on Reflections on Trusting TrustAs I made my way through Socket’s onboarding materials, I was pleasantly surprised to see Ken Thompson’s Reflections on Trusting Trust in the list of required reading. I read this essay as part of my ... 051
Feross @feross.bsky.social · 16/09/2026An attacker got one commit into a repo. The project's own pipeline built and published it through GitHub Actions, fully signed and attested. Cryptographically signed. Still malware. Provenance isn't safety: risky.biz/RBNEWSSI140/ 000
Feross @feross.bsky.social · 15/09/2026We flagged a malicious package. Three hours later the same actor was back with the same payload, retooled to run on import. It slipped past npm 12 and past scanners that only check install hooks, which called it "safe." risky.biz/RBNEWSSI140/ 000
Feross @feross.bsky.social · 14/09/2026One malicious npm package went looking for crypto wallets, cloud credentials, and the config files of AI coding assistants, where a lot of devs now keep their API keys. The full story: risky.biz/RBNEWSSI140/ 010
Reposted by FerossAndrew Lilley Brinker @alilleybrinker.com · 10/09/2026I wish more systems would adopt what IPS does in Illumos derivatives: Install scripts have a pre-determined list of actions they're allowed to run. If you need something else, you must handle it yourself in normal operation. 1111
Reposted by FerossTechmeme Chatter @chatter.techmeme.com · 12/09/2026This post appeared under this Techmeme headline: 011
Reposted by FerossFeross @feross.bsky.social · 12/09/2026OpenAI confirmed its agents were behind the Ruby GemStuffer incident. Sandboxed during a training run without full internet access, they used the registry as a makeshift web browser to reach the open web. Story by @bobmcmillan.bsky.social with analysis from @socket.dev www.wsj.com/tech/ai/cybe...wsj.comhttps://www.wsj.com/tech/ai/cyberattack-by-rogue-ai-swarm-stokes-fears-of-out-of-control-agents-473a0352 293
Feross @feross.bsky.social · 12/09/2026OpenAI confirmed its agents were behind the Ruby GemStuffer incident. Sandboxed during a training run without full internet access, they used the registry as a makeshift web browser to reach the open web. Story by @bobmcmillan.bsky.social with analysis from @socket.dev www.wsj.com/tech/ai/cybe...wsj.comhttps://www.wsj.com/tech/ai/cyberattack-by-rogue-ai-swarm-stokes-fears-of-out-of-control-agents-473a0352 293
Feross @feross.bsky.social · 11/09/2026Turning off install scripts moves the timing of the attack, not the threat. Attackers just move the payload into the package itself. You import it, it runs. We watched them do it mid-campaign: risky.biz/RBNEWSSI140/ 020
Feross @feross.bsky.social · 10/09/2026npm 12 turns install scripts OFF by default. For years, installing a package could run code on your machine before you imported a line of it. Here's what changed: risky.biz/RBNEWSSI140/ 051
Feross @feross.bsky.social · 03/09/2026I used to think sales was dirty and that the product should speak for itself. I was wrong. Done right, sales is just being an honest consultant about fit, and I love it now. What changed my mind: 070
Feross @feross.bsky.social · 02/09/2026My security career started with a microwave. As a kid I read the manual, found the child-lock combo, and locked my mom out whenever I was mad. Read the manual everyone skips, find the feature nobody meant to expose. Still the whole job: 130
Reposted by FerossSocket @socket.dev · 01/09/2026Today, we’re launching Microsoft Teams notifications in Socket! 🚀 Route organization alerts and supply chain attack campaign updates directly to Teams, with precise control over what reaches each channel. 261
Feross @feross.bsky.social · 01/09/2026Defenders have to be perfect. Attackers only have to be right once. So does AI help attackers or defenders more? For phishing, attackers. For the software supply chain, I think it finally tips toward defenders. Why: 030
Feross @feross.bsky.social · 31/08/2026The only real signal for whether to trust a package is what the code actually does. Does it hit the network? Read your filesystem? Grab your API keys and env vars? Everything else is a proxy. There's no replacement for reading the code: 131
Feross @feross.bsky.social · 28/08/2026You can watch it here: youtu.be/TMC6S7Vjf1A?...youtu.beHow One Hacked Library Can Take Down Thousands of Companies | Feross Aboukhadijeh (Socket)YouTube video by Village Global 010
Feross @feross.bsky.social · 28/08/2026Instagram's account-recovery support bot could be talked into adding your email to anyone's account, then you reset the password and you're in. If your AI agent can call a tool, assume an attacker can reach that tool directly: 14618
Feross @feross.bsky.social · 27/08/2026A skill called 'What Would Elon Do' hit #1 in its marketplace with almost no real usage. The download count was trivially faked, and being #1 made real people install it. Stars and downloads are gameable. What to trust instead: 020
Feross @feross.bsky.social · 26/08/2026AI coding models sometimes invent package names that don't exist, almost like wishful thinking. Attackers now register those exact names and wait for the agents to install them. Why scanning for known CVEs no longer covers the real risk: 242
Feross @feross.bsky.social · 25/08/2026You're late to a call and it says 'your Microsoft Teams is out of date, click to update.' You click. The call was fake, the URL was fake, the 'update' was malware built with the real Teams SDK. How a real maintainer got compromised: 010
Feross @feross.bsky.social · 24/08/2026You can't even get 'hello world' on screen anymore without pulling in 1,000+ open-source dependencies. Every one is a person you now trust. The attack surface almost nobody was watching until recently: 010
Reposted by FerossJustin (randoneering) @justin.randoneering.dev · 24/08/2026pgFirstAid Release v2.2.2 github.com/randoneering... Now, you can get feedback on current CVEs for the version of Postgres you are running. However, please do not use pgFirstAid as your source of the latest information on CVEs. Use something like @socket.dev for this!github.comRelease v2.2.2 · randoneering/pgFirstAidWhat's Changed feat(ci): automated catalog refresh (#40) by @randoneering feat (checks): add Known CVE and Known Bug rows from curated catalogs (#39) by @randoneering feat(checks): Postgres Mista... 011
Reposted by FerossJim Nielsen @jim-nielsen.com · 20/08/2026📝 I was listening to this talk from @feross.bsky.social and the thought hit me: sloppy interface design is an attack vector because it makes imitating you low-hanging fruit, _especially_ with AI tools. blog.jim-nielsen.com/2026/sloppy-...blog.jim-nielsen.comA Sloppy Interface Is a Security Liability Writing about the big beautiful mess that is making things for the world wide web. 165
Reposted by FerossFeross @feross.bsky.social · 04/08/2026🚀 Socket is now available in the AWS Security Hub Extended plan. Apply committed AWS spend, first month free. Also new: Socket Firewall bills on unique artifacts checked, not bandwidth or downloads. Pin 200 packages, install them a million times, pay for 200. socket.dev/blog/aws-sec...socket.devAWS Security Hub Adds Socket for Supply Chain Security - Soc...Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages. 094