Log inSign up
Philipp Burckhardt
6,943 posts
Philipp Burckhardt profile banner
@burckhap

Philipp Burckhardt

@burckhap
⚡Securing Software Supply Chains at @SocketSecurity (socket.dev) 🔭 Scientific computing for the web via @stdlibjs (stdlib.io)
Pittsburgh, PA
philipp-burckhardt.com
Joined October 2010
1,749
Following
1,608
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @burckhap
    Philipp Burckhardt
    @burckhap
    Jul 18, 2023
    GraphMaker for easy graph building: describe in English what nodes and edges you want, and it handles the rest via OpenAI's help. Support for trees, DAGs, styling, saving in multiple formats etc. Work in progress, please send @CRGenovese and me feedback!
    Image
    GitHub - isle-project/graphmaker: GraphMaker is a tool for creating, manipulating, and exporting...
    From github.com
  • @burckhap
    Philipp Burckhardt
    @burckhap
    18h
    GPT-6 Astra is a beast with Blender. I decided to test its limits and tasked it with building me geometry that changes and deforms at runtime, rendered in @threejs . Not the highest-value use of a Sunday evening, but I ended up with a fun little disaster game demo (with sound)
    Image
    00:00
    21
  • @burckhap
    Philipp Burckhardt
    @burckhap
    Apr 22
    Today, Socket detected malicious Namastex.ai npm packages that appear to replicate TeamPCP-style Canister Worm patterns, including exfiltration and self-propagation.
    Image
    Namastex Labs
    From namastex.ai
    1
  • @burckhap
    Philipp Burckhardt
    @burckhap
    Mar 14
    We identified 72 malicious Open VSX extensions linked to the GlassWorm campaign, including many cases where the malware is distributed transitively by being delilvered via covert extension packs. See below for link to our full coverage.
  • @burckhap
    Philipp Burckhardt
    @burckhap
    Sep 26, 2025
    While we haven't seen major supply chain attacks hitting any of the major open-source ecosystems, the Socket Threat Research Team uncovered some fascinating and creative attack techniques worth sharing:
    1
Advertisement
Advertisement