1. X
  2. Feross
Log inSign up
Feross
Socket
28.9K posts
Image
user avatar
Feross
Socket
@feross
⚡️ Founder + CEO @SocketSecurity (socket.dev) • 🌲 Visiting lecturer @Stanford (cs253.stanford.edu) • ❤️ Open source @WebTorrentApp + @StandardJS
Stanford, CA
feross.org
Joined August 2008
1,659
Following
41.2K
Followers
RepliesRepliesArticlesArticlesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    user avatar
    Feross
    Socket
    @feross
    May 24
    🚨 Active supply chain attack spanning npm, PyPI, and Crates.io simultaneously. Socket is tracking a campaign we’re calling TrapDoor: 34+ malicious packages and 384+ versions designed to steal crypto wallets, SSH keys, AWS credentials, GitHub tokens, browser data,
    Image
    34K
  • user avatar
    Feross
    Socket
    @feross
    4h
    Composer and @packagist serve billions of package installs a year. For most of their history, they've been funded largely by a single company. This week @naderman and @seldaek announced a sponsorship program and @SocketSecurity signed on as a launch sponsor. Here's why. When a
    4.7K
  • user avatar
    Feross
    Socket
    @feross
    12h
    “Just use an npm package” @SocketSecurity
    Image
    user avatar
    Feross
    Socket
    00:00
    user avatar
    Feross
    Socket
    1.7K
  • user avatar
    Feross
    Socket
    @feross
    Jul 30
    Socket signed the open letter on open-weight AI models, alongside Microsoft, Google, Meta, OpenAI, and NVIDIA. We're a 100-person startup, and this is one of the few policy letters we've ever signed. @SocketSecurity exists because open ecosystems get attacked. We block 10,000+
    Image
    Image
    23K
  • user avatar
    Feross
    Socket
    @feross
    Jul 29
    It's actually true.
    user avatar
    Village Global
    @villageglobal
    Jul 29
    "One of the best defenses against being phished is just being too busy to read your email." @feross, Founder and CEO of @SocketSecurity, on how attackers compromised one of the most widely used JavaScript libraries: "There's a maintainer who runs that project. He received an
    Image
    00:00
    3.7K
  • See @feross's full profile

    Sign up
    Log in
Advertisement
Advertisement