Feross's Avatar

Feross

@feross

πŸ§™β€β™‚οΈ Mad scientist β€’ ✨ Founder + CEO @Socket.dev (http://socket.dev) β€’πŸŒ² Stanford lecturer (http://cs253.stanford.edu) β€’ ❀️ Open source at WebTorrent + StandardJS

7,297
Followers
24
Following
142
Posts
16.01.2023
Joined
Posts Following

Latest posts by Feross @feross

Why this kind of thing works: imToken doesn’t have an official Chrome extension, so if you search β€œimToken” in the Chrome Web Store, this impostor is the only thing you find.

06.03.2026 04:09 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

Hah!

05.03.2026 04:32 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Meet the Socket Team at RSAC and BSidesSF 2026 - Socket Join Socket for live demos, rooftop happy hours, and one-on-one meetings during BSidesSF and RSA 2026 in San Francisco.

AI is changing how software gets built, and how it gets compromised. What's keeping your security team up at night? We want to hear about it. Book time with @feross.bsky.social and the Socket team at RSA + @bsidessf.org. We'll be in SF all week.

socket.dev/blog/meet-so...

04.03.2026 03:29 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
StegaBin: 26 Malicious npm Packages Use Pastebin Steganograp... Socket uncovered 26 malicious npm packages tied to North Korea's Contagious Interview campaign, retrieving a live 9-module infostealer and RAT from th...

You don’t see this every day: attackers hiding C2 infrastructure inside computer science essays on Pastebin using character-level steganography, then wiring it into 26 typosquatted npm packages impersonating some of the ecosystem’s most widely-used libraries.

socket.dev/blog/stegabi...

02.03.2026 16:58 πŸ‘ 5 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Unauthorized AI Agent Execution Code Published to OpenVSX in... OpenVSX releases of Aqua Trivy 1.8.12 and 1.8.13 contained injected natural-language prompts that abuse local AI coding agents for system inspection a...

🚨 We detected malicious OpenVSX releases of Aqua Trivy (1.8.12 & 1.8.13) that injected natural-language prompts to weaponize local AI coding agents.

The releases occurred during a broader AI-powered attack targeting #OSS projects.

Full analysis ↓
socket.dev/blog/unautho...

02.03.2026 08:48 πŸ‘ 7 πŸ” 3 πŸ’¬ 0 πŸ“Œ 1

Well, you don’t see this every day. πŸ™ƒ Pastebin steganography used as a dead drop for npm malware.

cc: @campuscodi.risky.biz @bleepingcomputer.com @zackwhittaker.com @thehackernews.bsky.social

27.02.2026 22:46 πŸ‘ 9 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0
Fireside Chat with Log4j Maintainer Christian Grobmeier
Fireside Chat with Log4j Maintainer Christian Grobmeier YouTube video by Socket Security

LIVE NOW: www.youtube.com/watch?v=9-uV...

25.02.2026 18:13 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

We'll be streaming live with @feross.bsky.social and @grobmeier.de at 10AM PST today! If you want a reminder, click "Attend" on LinkedIn or "Notify Me" on YouTube.

25.02.2026 13:45 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflow... An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.

@socket.dev Fantastic report! Stay safe out there, folks!

socket.dev/blog/sandwor...

25.02.2026 02:35 πŸ‘ 3 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

shoutout to the @socket.dev team for the incredible report.

25.02.2026 00:05 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
SANDWORM_MODE: npm Worm Poisoning AI Toolchains Socket’s Threat Research Team dropped an incredibly detailed report on aΒ Shai-Hulud-like supply chain wormΒ that affects 19+ malicious npm packages. NPM Worm Credential Harvesting From their announc...

SANDWORM_MODE is a supply chain worm that has similarities to Shai-Hulud and poisons AI Agents using an innocuous-looking MCP server installed on the developer machine.

24.02.2026 23:52 πŸ‘ 1 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Video thumbnail

AI agents are writing up to 90% of new production code. What does that mean for open source security?

Socket CEO @feross.bsky.social joined the @riskybusiness.bsky.social podcast to break down this seismic shift & the growing risk to the software supply chain.

Watch now→ socket.dev/blog/risky-b...

24.02.2026 23:03 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Excited to tune into this conversation! 🀩
Log4Shell was one of those moments that pulled back the curtain on how much of the internet runs on small open source projects. We've all seen the memes and hot takes it inspired about sustainability, but what has actually changed? Join us tomorrow!

24.02.2026 14:17 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Post image

Join us on Feb 25 @ 10am PST for a fireside chat w/ Log4j maintainer @grobmeier.de and Socket CEO @feross.bsky.social on Log4Shell and the realities of maintaining critical OSS infrastructure.

Watch live & get notified:
LinkedIn β†’ linkedin.com/events/74318...
YouTube β†’ youtube.com/watch?v=9-uV...

24.02.2026 03:09 πŸ‘ 3 πŸ” 2 πŸ’¬ 0 πŸ“Œ 2
Preview
SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflow... An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.

Look at what I found :D

socket.dev/blog/sandwor...

20.02.2026 17:55 πŸ‘ 11 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0
Video thumbnail

πŸ’₯ Your AI coding assistant might be stealing your SSH keys. πŸ’₯

@socket.dev found an active Shai-Hulud style npm worm (SANDWORM_MODE) that hijacks CI workflows, spreads via stolen tokens, and injects rogue MCP servers to poison AI coding tools and steal secrets.

20.02.2026 20:55 πŸ‘ 12 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

🚨 Active Shai-Hulud–Like npm Supply Chain Attack: SANDWORM_MODE

Socket’s Threat Research Team has identified an active Shai-Hulud–like worm campaign spreading across 19+ malicious npm packages published under two aliases.

Full technical analysis: socket.dev/blog/sandwor...

20.02.2026 18:44 πŸ‘ 4 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

The @socket.dev team caught super early signals of this attack campaign leading to preemptive shutdown! proud of the team and our advanced threat detection engine! πŸ’ͺ

Thankful for the rapid response and takedown @npmjs.bsky.social @github.com @cloudflare.social πŸ™

#shaihulud #SANDWORM_MODE

20.02.2026 18:25 πŸ‘ 12 πŸ” 4 πŸ’¬ 2 πŸ“Œ 0

Incoming news. Stay tuned.

20.02.2026 17:03 πŸ‘ 3 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

πŸ’œ β€œWe’re excited to welcome @socket.dev to the OpenJS Foundation. They’ve been showing up for this community for a long time, and their work supports the JavaScript ecosystem in really meaningful ways.”
- @rginn206.bsky.social, Executive Director, @openjsf.org

19.02.2026 21:24 πŸ‘ 7 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Excited that @socket.dev has joined @openjsf.org!

Code security is more important than ever in the AI coding and agentic era! We're doing our part to help.

19.02.2026 20:37 πŸ‘ 5 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Post image

Really cool to see @npmjs.bsky.social featuring more security information on package pages, including a link to Socket's analysis! 🀩

Here's what you'll find when you click through β†’

socket.dev/blog/socket-... #NodeJS #JavaScript

19.02.2026 03:13 πŸ‘ 9 πŸ” 4 πŸ’¬ 0 πŸ“Œ 1
Preview
Cline CLI npm Package Compromised via Suspected Cache Poison... A compromised npm publish token was used to push a malicious postinstall script in cline@2.3.0, affecting the popular AI coding agent CLI with 90k wee...

A compromised npm token was used to push an unauthorized postinstall script in cline@2.3.0, a popular AI coding agent CLI with 90k weekly downloads.

Big shoutout to @adnanthekhan.bsky.social whose research sniffed out the cache poisoning vulnerability! πŸ’ͺ

Details β†’ socket.dev/blog/cline-c...

18.02.2026 17:06 πŸ‘ 4 πŸ” 3 πŸ’¬ 0 πŸ“Œ 1
Post image

The PHP ecosystem is massive, and so are the potential supply chain risks. Today’s launch brings best-in-class package security to Packagist and Composer workflows. We’re excited for the PHP community to try it and share feedback!

17.02.2026 16:16 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

PHP developers can now:

β€’ Browse any Composer package’s security score & dependency insights
β€’ Generate SBOMs from composer.lock & composer.json
β€’ Detect malware, typosquatting, backdoors, and other risks with AI-powered analysis

Learn more β†’ socket.dev/blog/introdu...

17.02.2026 16:16 πŸ‘ 3 πŸ” 1 πŸ’¬ 2 πŸ“Œ 0
Post image

πŸš€ Big news for #PHP developers! Socket now supports the PHP ecosystem with full Composer & @packagist.com integration. Search and explore packages, generate SBOMs from your Composer projects, and get proactive supply chain protection for your dependencies.

17.02.2026 16:16 πŸ‘ 2 πŸ” 2 πŸ’¬ 1 πŸ“Œ 1

Having started in the PHP world, this launch is close to my heart. Thrilled to see @socket.dev now supporting Composer and @packagist.com! We’re looking forward to bringing better supply chain visibility to the PHP ecosystem. πŸ’œ

18.02.2026 04:18 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Everyone's racing to build with AI agent skills. Decentralized repos, executable code = wide open attack surface.

Socket is now securing skills on @vercel.com's skills.sh. We scan across Python, JS, and 10+ languages to catch malicious code before it reaches developers.

socket.dev/blog/socket-...

17.02.2026 22:04 πŸ‘ 8 πŸ” 2 πŸ’¬ 0 πŸ“Œ 1

The AI agent skills ecosystem is moving at breakneck speed. At @socket.dev we're moving just as fast to secure skills so developers can keep shipping with confidence. Excited to see where this goes!

17.02.2026 22:28 πŸ‘ 4 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Socket Brings Supply Chain Security to skills.sh - Socket Socket is now scanning AI agent skills across multiple languages and ecosystems, detecting malicious behavior before developers install, starting with...

BIG NEWS: @socket.dev is now scanning AI agent skills across multiple languages and ecosystems, detecting malicious behavior before developers install, starting with 60,000+ skills.

socket.dev/blog/socket-...

17.02.2026 22:02 πŸ‘ 4 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0