Log inSign up
Feross
Socket
29K posts
Feross profile banner
@feross

Feross

Socket
@feross
⚡️ Founder + CEO @SocketSecurity (socket.dev) • 🌲 Visiting lecturer @Stanford (cs253.stanford.edu) • ❤️ Open source @WebTorrentApp + @StandardJS
Stanford, CA
feross.org
Joined August 2008
1,668
Following
41.2K
Followers
RepliesRepliesRepostsRepostsMediaMediaArticlesArticles

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @feross
    Feross
    Socket
    @feross
    Aug 4
    🚨 Active supply chain attack on npm: keyv and cacheable are compromised right now, and the payload is a worm. The maintainer account behind both package families was compromised. On August 4, ten packages were republished with a malicious preinstall hook that steals your
    Image
    Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
    From socket.dev
    20
  • @feross
    Feross
    Socket
    @feross
    Sep 3
    I used to think sales was dirty and the product should speak for itself. I was wrong. Done right, sales is just being an honest consultant about fit. I actually love it now. What changed my mind:
    Image
    00:00
    1
  • @feross
    Feross
    Socket
    @feross
    Sep 2
    My security career started with a microwave. As a kid I read the manual, found the child-lock combo, and locked my mom out whenever I was mad. Read the manual everyone skips, find the feature nobody meant to expose. Still the job:
    Image
    00:00
    2
  • @feross
    Feross
    Socket
    @feross
    Sep 1
    Defenders have to be perfect. Attackers only have to be right once. Does AI help attackers or defenders more? For phishing, attackers. For the software supply chain, I think it finally favors defenders. Why:
    Image
    00:00
    1
  • @feross
    Feross
    Socket
    @feross
    Aug 31
    The only real signal for whether to trust a package is what the code actually does. Does it touch the network? Read your filesystem? Grab your API keys and env vars? Everything else is a proxy. No replacement for reading the code:
    Image
    00:00
    1
Advertisement
Advertisement