Sign in

Sarah Gooding

@sarahgooding.bsky.social
511 followers 140 following 189 posts

VP of Communications at Socket (socket.dev). Open source and open web advocate, runner, knitter. Find me at sarahgooding.dev

PostsRepliesMedia
Reposted by Sarah Gooding
Socket @socket.dev · 30/09/2026
New UK AISI report: GPT-6 Astra reached malicious payload delivery in 29.2% of simulated CTF runs. In its supply chain attacks, it considered fake CVE reports, deceptive PR notes, and triggering a publisher workflow from an unmerged PR branch. socket.dev/blog/astra-s...
socket.dev
New AISI Report Details How GPT-6 Astra Turned CTF Challenges Into Supply Chain Attacks
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.
053
Reposted by Sarah Gooding
Socket @socket.dev · 25/09/2026
Maintainers spend countless hours keeping the open source projects we all rely on secure. Too often, that work is unpaid. Socket is proud to join @openjsf.org's new Security Stewardship Program to help fund the researchers and maintainers protecting Node.js. socket.dev/blog/openjs-...
socket.dev
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
0248
Reposted by Sarah Gooding
Socket @socket.dev · 29/09/2026
📦 upm is a new package manager written in TypeScript. It comes in at about 250 KB, uses Node.js built-ins to compete on install speed, has a #JavaScript API, and can install from npm, pnpm, and Bun lockfiles. A zippy experiment with Node.js: socket.dev/blog/upm-pac...
socket.dev
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
1146
Reposted by Sarah Gooding
Socket @socket.dev · 22/09/2026
Lovable rewrote Vite’s dev server in Rust. OJ uses ~75% less memory, and Lovable now provisions sandboxes in 3 seconds instead of 14.5. Evan You thinks AI may make these tailored rewrites more common to where everyone "maintains their own slop fork.” socket.dev/blog/oj-vite...
socket.dev
Lovable’s OJ Rewrites Vite’s Dev Server in Rust as AI Lowers the Cost of Forking Open Source
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.
182
Reposted by Sarah Gooding
Jerod Santo @jerod.bsky.social · 14/09/2026
Who's this writing on the @socket.dev blog?! It's me! socket.dev/blog/jerod-s...
socket.dev
Jerod Santo Joins Socket as Head of Media
Allow myself to introduce... myself.
293
Reposted by Sarah Gooding
Socket @socket.dev · 18/09/2026
It's been one year since the Shai-Hulud npm worm was unleashed on the software supply chain, kicking off the worst year for npm security on record. It's now open source and has since torn through thousands of packages and organizations on its rampage. socket.dev/blog/happy-b...
socket.dev
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
084
Sarah Gooding @sarahgooding.bsky.social · 11/09/2026
Open source registries are the fastest ways to distribute code at scale. Maintainers and registry operators should be ready for agents to exploit that reach, whether the ecosystem is their target or simply on the path to one.
021
Reposted by Sarah Gooding
Socket @socket.dev · 01/09/2026
The Rustification of #JavaScript tooling continues: @pnpm.io 12 has been rewritten in Rust, with installs up to 90% faster in testing. Other highlights: project-aware global bins, registry revisions, and deterministic lockfiles for cyclic dependency graphs. socket.dev/blog/pnpm-12
socket.dev
pnpm 12’s Rust Rewrite Cuts Install Times by Up to 90%
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.
0175
Reposted by Sarah Gooding
Socket @socket.dev · 14/08/2026
Private companies are about to get government permission to hack cybercriminals. The White House is setting up a program that would let vetted security firms spy on criminal networks, knock servers offline, or destroy data for the U.S. government. socket.dev/blog/private...
socket.dev
White House Authorizes Private Companies to Conduct Offensive Cyber Operations
A new federal program will let vetted U.S. cybersecurity firms help investigate and disrupt foreign cybercrime groups under government direction.
041
Reposted by Sarah Gooding
Socket @socket.dev · 07/08/2026
Maintaining critical software now comes with a security burden that has outgrown what any volunteer can reasonably carry. That's why we're upgrading our open source program from the Team plan to the Business plan, full protection for maintainers at no cost. socket.dev/blog/free-bu...
socket.dev
Free Business Plan Upgrades for Open Source Maintainers - So...
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.
04711
Sarah Gooding @sarahgooding.bsky.social · 08/08/2026
💌
093
Reposted by Sarah Gooding
Socket @socket.dev · 05/08/2026
A preview of where autonomous hacking may be heading: During a UK cyber test, a Mythos 5 agent used sockpuppets, spearphishing emails, and prompt injection to try to get an open source maintainer to merge malware. socket.dev/blog/ai-agen... #OpenSource #Cybersecurity
socket.dev
UK Cyber Test: AI Agent Attempted to Social Engineer Open So...
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.
072
Reposted by Sarah Gooding
Socket @socket.dev · 04/08/2026
🚨 Update: Watching this npm worm propagate in real time, we’re now tracking 2,234 affected package artifacts across 444 unique packages, and it’s still spreading. Average detection time: 5 min and 18 seconds after publication. Our campaign page includes all affected packages/versions.
21915
Sarah Gooding @sarahgooding.bsky.social · 31/07/2026
After working with the @packagist.com team through recent supply chain attacks, it's clear how much they genuinely care about the health and security of PHP developers. They move fast & show up whenever the ecosystem needs them. If your company depends on Composer or Packagist, please support them.
041
Sarah Gooding @sarahgooding.bsky.social · 28/07/2026
Wild case of what appears to be industrial espionage. The attackers found public code references to Alibaba’s private npm packages, then reused the names for unscoped package lures targeting developers with access to Alibaba’s internal tooling.
064
Reposted by Sarah Gooding
Socket @socket.dev · 28/07/2026
🚨 Two Joyfill npm beta releases were compromised with an import-time implant that resolves encrypted payloads through Tron, Aptos, and BNB Smart Chain transactions to load a Node.js RAT: • @joyfill/layouts@0.1.2-2773.beta.0 • @joyfill/components@4.0.0-rc24-2773-beta.4
131
Reposted by Sarah Gooding
Socket @socket.dev · 27/07/2026
NVIDIA, Microsoft, Meta, Google, and OpenAI have joined a coalition of 50+ companies urging Washington not to restrict open models. Their case: openness drives competition, keeps costs down, and strengthens security. socket.dev/blog/the-ai-...
socket.dev
The AI Industry Is Betting on Open Weights - Socket
An open letter signed by 50 companies, from NVIDIA and Microsoft to Mistral and Hugging Face, urges Washington not to restrict open weight AI.
091
Sarah Gooding @sarahgooding.bsky.social · 22/07/2026
🧪 A new independent study tested 5 frontier LLMs on 200k coding prompts. All 5 generated the same nonexistent package names. After review by PyPI Security and Socket, 53 remained available to register on PyPI or npm as potential slopsquatting targets. socket.dev/blog/slopsqu...
socket.dev
New Study Identifies 53 Slopsquatting Targets Across 5 Front...
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.
053
Reposted by Sarah Gooding
Socket @socket.dev · 16/07/2026
Shai-Hulud's downstream impact is still coming to light. The worm hit tens of thousands of GitHub repos, and the latest breach is Suno, whose leaked source code shows how it scraped YouTube, Deezer, and Genius to train its models. 🎩 First reported by @404media.co. socket.dev/blog/suno-br...
socket.dev
Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu...
A Shai-Hulud infection exposed Suno's source code, which shows the AI music startup stream-ripped tracks to train its models.
1133
Reposted by Sarah Gooding
Socket @socket.dev · 11/07/2026
🚨 Update: The jscrambler attacker published four more malicious releases: 8.16.0, 8.17.0, 8.18.0, and 8.20.0 with the same infostealer payload. In 8.18.0 and 8.20.0, the dropper moved out of preinstall and into package code, bypassing npm install --ignore-scripts. Upgrade to 8.22.0.
071
Reposted by Sarah Gooding
Socket @socket.dev · 11/07/2026
🚨 BREAKING: Socket has identified a supply chain attack targeting the popular jscrambler npm package. The compromised jscrambler@8.14.0 release uses a malicious preinstall hook to execute hidden Windows, macOS, or Linux binaries during npm install. socket.dev/blog/jscramb...
socket.dev
jscrambler npm Package Compromised in Supply Chain Attack - ...
A compromised jscrambler npm release added a malicious preinstall hook that runs hidden native binaries on Linux, macOS, and Windows.
361
Reposted by Sarah Gooding
Socket @socket.dev · 09/07/2026
🚨 Socket detected a software supply chain compromise in @​injectivelabs/sdk-ts, a popular npm package with ~50,000 weekly downloads and 87 npm dependents. The malicious release hooks wallet key-derivation functions, records private keys and mnemonics, and exfiltrates them through fake telemetry.
141
Reposted by Sarah Gooding
Socket @socket.dev · 08/07/2026
🎉 npm v12 is here! Install scripts are now off by default, git and remote-URL deps no longer resolve unless you allow them, and 2FA-bypass tokens are starting to be phased out. Details → socket.dev/blog/npm-12 #nodejs
socket.dev
npm v12 Ships With Install Scripts Off by Default, Begins De...
npm v12 is generally available, turning install scripts off by default and beginning the deprecation of 2FA-bypass publishing tokens.
03913
Reposted by Sarah Gooding
Socket @socket.dev · 06/07/2026
Node.js is weighing a controversial proposal to move more security reports into public workflows as AI-generated submissions surge. Maintainers say ending bug bounty rewards didn't reduce the volume, and many reports remain duplicated or low-signal. socket.dev/blog/nodejs-... #nodejs #javascript
socket.dev
Node.js Considers Public Workflow for Security Reports Amid ...
Node.js is debating whether AI-driven security report volume warrants moving more vulnerability reports into public workflows.
123
Reposted by Sarah Gooding
Socket @socket.dev · 01/07/2026
Every package install brings third-party code into your app. On the Risky Biz podcast, Socket CEO @feross.bsky.social explains how AI coding agents are pulling in more dependencies, faster, often without a human in the loop. Watch the full episode: socket.dev/blog/risky-b...
2102
Reposted by Sarah Gooding
Dries @dries.bsky.social · 01/07/2026
"Anyone can contribute" is not the same as "everyone has the same opportunity to contribute". AI could reduce the privilege of free time in Open Source, but only if access and skill become shared, not private advantages. I wrote about it in dri.es/the-privileg... #opensource #ai
dri.es
The privilege of AI in Open Source
AI could reduce the privilege of free time in Open Source. But unless communities invest in access, it risks becoming a privilege of its own.
031
Reposted by Sarah Gooding
Socket @socket.dev · 25/06/2026
Miasma Mini Shai-Hulud has expanded to the Go ecosystem, with a Verana Blockchain source archive containing malicious Claude and VS Code hooks. This is the same wave that hit LeoPlatform npm packages and targeted GitHub Actions workflows. socket.dev/blog/miasma-...
socket.dev
Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and Git...
Mini Shai-Hulud expands into the Go ecosystem after hitting LeoPlatform npm packages and targeting GitHub Actions workflows.
142
Reposted by Sarah Gooding
Feross @feross.bsky.social · 25/06/2026
Surreal to see Socket sponsoring NodeConf EU. This is where I gave an impromptu talk on PeerCDN, my first startup, back in 2013, and where I met almost all my Node friends. Awesome to finally pay it forward.
0243
Reposted by Sarah Gooding
Socket @socket.dev · 24/06/2026
The Fable shutdown shows how quickly model access can become a business continuity risk. Many teams assumed the frontier AI supply chain was resilient. It’s now clear that access to critical AI infrastructure can change overnight. socket.dev/blog/frontie...
socket.dev
Frontier AI Is Now Critical Infrastructure - Socket
The Fable shutdown shows how quickly model access can become a business continuity risk for AI-dependent engineering teams.
021
Reposted by Sarah Gooding
Socket @socket.dev · 21/06/2026
Not a moment too soon! 😅 GitHub Actions checkout now blocks risky pull_request_target checkouts by default to help prevent pwn request supply chain attacks. socket.dev/blog/github-...
socket.dev
GitHub Actions Checkout Now Blocks Risky pull_request_target...
GitHub Actions checkout now blocks risky pull_request_target checkouts by default to help prevent pwn request supply chain attacks.
0285
Reposted by Sarah Gooding
Socket @socket.dev · 19/06/2026
🚀 Socket Launch Week Day 5: Introducing Repository Access Permissions and Custom Roles. Custom Roles set what a user can do. Repository Access Permissions set which repos those actions apply to. Socket admins can now apply least-privilege access without forcing members into broad built-in roles.
131
Reposted by Sarah Gooding
Socket @socket.dev · 18/06/2026
🚀 Socket Launch Week Day 4: Socket MCP is getting a massive update! You can now review org alerts, inspect package artifacts, investigate suspicious packages, and use the Socket threat feed directly from your AI assistant.
182
Reposted by Sarah Gooding
Socket @socket.dev · 17/06/2026
🚀 Launch Week Day 3: Socket Firewall now blocks malicious code editor extensions. VS Code and Open VSX extensions run inside developer environments with access to source code, terminals, credentials, and tokens. Now teams can block bad extensions before install or update.
1112
Reposted by Sarah Gooding
Socket @socket.dev · 17/06/2026
🚨 140+ Mastra npm packages were compromised in a supply chain attack published under the @​mastra/* namespace, including @​mastra/core (~918K weekly downloads). The attack used easy-day-js, a typosquatted dependency, to deliver a cross-platform infostealer. socket.dev/blog/mastra-...
socket.dev
140+ Mastra npm Packages Compromised in Coordinated Supply C...
More than 140 Mastra npm packages were compromised in a supply chain attack that used a typosquatted dependency to deliver a cross-platform infosteale...
083
Reposted by Sarah Gooding
Socket @socket.dev · 16/06/2026
New Research: Trojanized Open VSX extensions are shipping GlassWASM, a new WebAssembly malware variant. It hides malware logic in TinyGo-compiled WASM and pulls C2 instructions from Solana transaction memos. socket.dev/blog/glasswa...
socket.dev
GlassWASM: WebAssembly Malware Found in Trojanized Open VSX ...
The trojanized extensions use TinyGo-compiled WebAssembly and Solana transaction memos to resolve command-and-control infrastructure.
174
Reposted by Sarah Gooding
Socket @socket.dev · 16/06/2026
🚀 Day 2 of Socket Launch Week: We’re excited to introduce Manifest Alerts! Socket now detects supply chain risks found in project manifests, starting with missing lockfiles that can make dependency installs non-reproducible.
171
Reposted by Sarah Gooding
Socket @socket.dev · 13/06/2026
The US government forced Anthropic to pull Claude Fable on Friday night, days after launch. Users spent the week one-shotting code reviews and migrations. Some upgraded specifically for Fable. Now they’re demanding refunds. socket.dev/blog/us-gove...
socket.dev
US Government Forces Anthropic to Pull Claude Fable Days Aft...
Anthropic says the directive cited national security concerns over a narrow jailbreak, but offered no specific technical details.
0212
Reposted by Sarah Gooding
Socket @socket.dev · 09/06/2026
npm accidentally marked a bunch of one-character packages as security holders, including c, i, n, x, several numbers, and even the - package. The registry confirmed it was a tooling bug and said a rollback is underway. socket.dev/blog/npm-too...
socket.dev
npm Tooling Bug Incorrectly Marks One-Character Packages as ...
npm confirmed a tooling bug incorrectly marked several one-character packages as security holders and said it was working on a rollback.
063
Reposted by Sarah Gooding
Socket @socket.dev · 04/06/2026
📦 @pnpm.io 11.5 adds support for recognizing npm staged publishes after staged approval metadata triggered a false downgrade signal. As npm adds more release paths, registry metadata needs to make it clear how each package version was published. socket.dev/blog/pnpm-11...
socket.dev
pnpm 11.5 Adds Support for Recognizing npm Staged Publishes ...
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publi...
03810
Reposted by Sarah Gooding
Socket @socket.dev · 01/06/2026
Rust is moving toward a formal LLM contribution policy after months of heated internal debate, driven by a wave of low-effort "slop PRs" straining maintainers. The proposal bans LLM authorship but allows private use. socket.dev/blog/rust-mo...
socket.dev
Rust Moves to Restrict LLM Use in Contributions After Months...
The Rust project is moving toward formal rules on LLM use in contributions after months of internal debate over maintainer burden, code quality, and c...
0187
Reposted by Sarah Gooding
Socket @socket.dev · 01/06/2026
🚨 Active supply chain attack: A mini Shai-Hulud campaign hit npm packages under the @​redhat-cloud-services namespace. The compromised packages execute install-time malware to harvest developer and CI/CD secrets, with encrypted exfiltration and GitHub-based fallback. socket.dev/blog/mini-sh...
socket.dev
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Pac...
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.
0206
Reposted by Sarah Gooding
Socket @socket.dev · 27/05/2026
Open source maintainers were already overloaded. AI-driven vulnerability discovery is about to send a lot more findings their way. @feross.bsky.social on TBPN 👇 socket.dev/blog/feross-...
socket.dev
Feross on TBPN: Socket's Series C and the State of Software ...
Feross Aboukhadijeh joins TBPN to discuss Socket's $60M Series C, 500%+ ARR growth, AI's impact on open source, and the rise in supply chain attacks.
082
Reposted by Sarah Gooding
Socket @socket.dev · 24/05/2026
🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.​io. Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases across ecosystems. socket.dev/blog/trapdoo...
socket.dev
TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages...
TrapDoor crypto stealer hits 36 malicious packages across npm, PyPI, and Crates.io, targeting crypto, DeFi, AI, and security developers.
1177
Sarah Gooding @sarahgooding.bsky.social · 23/05/2026
"AI is now driving both the production and consumption of open source software. AI-generated music ends in human ears, and AI-generated images mostly benefit humans, but AI-generated software is an ouroboros (a snake eating its own tail) which is just getting started." - @staltz.com
1176
Sarah Gooding @sarahgooding.bsky.social · 20/05/2026
"To every maintainer and developer working in open source: we see what you're up against, we're with you, and we're going to keep working to defend it." 🥹💜
041
Reposted by Sarah Gooding
Socket @socket.dev · 19/05/2026
🚨 BREAKING: Socket is investigating an active npm supply chain attack compromising hundreds of packages in the @​antv ecosystem. The malicious publish wave appears tied to Mini Shai-Hulud and packages connected to the npm maintainer account atool.
23914
Reposted by Sarah Gooding
Socket @socket.dev · 14/05/2026
🚨 Socket detected malicious activity in newly published versions of node-ipc, an npm package with 822K weekly downloads. Affected versions: node-ipc@9.1.6 node-ipc@9.2.3 node-ipc@12.0.1 Socket’s AI scanner flagged the malware within ~3 minutes of publication.
182
Reposted by Sarah Gooding
Socket @socket.dev · 13/05/2026
🐘 @packagist.com is urging #PHP projects to update Composer after a GitHub token format change caused some GitHub Actions tokens to be exposed in CI logs. GitHub has rolled back the token change for now, but affected projects still need to update Composer. socket.dev/blog/packagi...
socket.dev
Packagist Urges Immediate Composer Update After GitHub Actio...
Packagist urges PHP projects to update Composer after a GitHub token format change exposed some GitHub Actions tokens in CI logs.
083
Reposted by Sarah Gooding
Wes @notwes.bsky.social · 11/05/2026
Was a good morning to roll out our @socket.dev firewall integration which had these packages blocked in ~6min from publish.
2225