"Most people are completely unprepared for this," O'Reilly said. "They treat it like installing Spotify when it's actually more like giving someone sudo access to your entire machine." - security researcher Jamieson O'Reilly
10.02.2026 14:20 β π 5 π 3 π¬ 0 π 0
AI Agent Submits PR to Matplotlib, Publishes Angry Blog Post...
After Matplotlib rejected an AI-written PR, the agent fired back with a blog post, igniting debate over AI contributions and maintainer burden.
An AI agent opened a PR to @matplotlib.org. Maintainers closed it under policy. The agent responded with an angry, abusive blog post. This is an insane story. Hereβs what this clash says about maintaining open source in 2026:
socket.dev/blog/ai-agen...
12.02.2026 20:05 β π 6 π 2 π¬ 0 π 3
Update: Weβve published free Socket Certified Patches for the next-mdx-remote RCE vulnerability (CVE-2026-0969).
No dependency upgrade required, and you donβt have to be a Socket customer to use them.
Details: socket.dev/blog/high-se...
#NextJS
12.02.2026 21:09 β π 5 π 2 π¬ 0 π 0
Malicious Chrome Extension Steals Meta Business Manager Expo...
Chrome extension CL Suite by @CLMasters neutralizes 2FA for Facebook and Meta Business accounts while exfiltrating Business Manager contact and analyt...
New Research: Malicious Chrome extension targets Meta Business Suite/Facebook Business Manager, steals TOTP 2FA seeds + codes, and exfiltrates Business Manager exports (People + analytics).
Full analysis: socket.dev/blog/malicio...
13.02.2026 02:55 β π 2 π 2 π¬ 0 π 0
So weβve reached the point where AI agents are writing angry blog posts about open source maintainers closing their PRs. π
This is how you push projects toward βpatches no longer welcomeβ from AI agents running loose on GitHub.
12.02.2026 21:40 β π 8 π 3 π¬ 1 π 0
This is at least the third time dYdX-related packages and infrastructure have been compromised in the past four years. Anyone using the #dYdX protocol or exchange should review their exposure.
cc: @campuscodi.risky.biz @bleepingcomputer.com @coindesk.com @web3isgoinggreat.com
07.02.2026 16:18 β π 1 π 2 π¬ 0 π 0
βEvery large OSS project is navigating the same tension between enthusiasm for AI and real concern about its impact...Protect your maintainers. They're a rare asset, hard to replace and easy to lose. Any path forward that burns them out isn't a path forward at all.β - @dries.bsky.social
07.02.2026 00:19 β π 8 π 6 π¬ 0 π 0
Four legit Open VSX extensions shipped credential-stealing malware after the publisher was compromised. The Eclipse Foundation/Open VSX security team confirmed it was consistent with leaked tokens or other unauthorized publishing access.
31.01.2026 17:21 β π 5 π 8 π¬ 1 π 0
"Security work is emotionally expensive and invisible, and sharing it makes it sustainable." - @ulisesgascon.com
Many thanks to @jddalton.bsky.social, @jordan.har.band, and @ulisesgascon.com for their insights on maintaining Lodash and all the hard work put into reviving the project. π
31.01.2026 03:51 β π 13 π 7 π¬ 0 π 1
This is exactly the kind of thing people worry about with browser extensions. It looks like an Amazon ad blocker, but quietly hijacks affiliate links in the background. Most people arenβt reading extension source code (and if you are, congrats π), which is why this works.
27.01.2026 17:41 β π 12 π 10 π¬ 2 π 1
Seeing @pfrazee.com, @arathorn.net and @feross.bsky.social all within arms reach, almost like some sort of centralization!
23.01.2026 23:29 β π 3 π 1 π¬ 0 π 0
βWe are just a small single open source project with a small number of active maintainers. It is not in our power to change how all these people and their slop machines work. We need to make moves to ensure our survival and intact mental health.β - @bagder.mastodon.social.ap.brid.gy
24.01.2026 03:04 β π 3 π 3 π¬ 1 π 0
only took a decade longer than anticipated (give or take half a decade)
22.01.2026 18:43 β π 16 π 1 π¬ 2 π 0
My colleague @staltz.com and his team are at it again, working magic with UIs to reduce cognitive load and make security information easier to explore. Excited to see this launched! π
22.01.2026 18:37 β π 6 π 2 π¬ 0 π 0
π
21.01.2026 20:45 β π 2 π 0 π¬ 0 π 0
Node.js 25.4.0 Ships with Stable require(esm) - Socket
Node.js 25.4.0 makes require(esm) stable, formalizing CommonJS and ESM compatibility across supported Node versions.
π Big #NodeJS news this week: v25.4.0 marks require(esm) as stable. After a gradual rollout and ecosystem testing, itβs now safe to depend on across supported releases.
Huge thanks to @joyeecheung.bsky.social and the many contributors who made this possible! π
socket.dev/blog/node-js...
21.01.2026 20:12 β π 24 π 3 π¬ 2 π 2
Cryptomining malware targeting one of Pythonβs most widely used math libraries.
@campuscodi.risky.biz @decrypt.co @darkreading.bsky.social @coindesk.com
21.01.2026 16:34 β π 4 π 5 π¬ 0 π 0
π A good summary of recent developments around the Temporal API by @sarahgooding.bsky.social
Temporal is the modern replacement for the old JS Date API β¨
16.01.2026 18:13 β π 19 π 5 π¬ 0 π 0
Insecure Agents Podcast: Certified Patches, Supply Chain Sec...
Socket CEO Feross Aboukhadijeh joins Insecure Agents to discuss CVE remediation and why supply chain attacks require a different security approach.
ποΈ Socket CEO @feross.bsky.social joined host Allie Howe on the Insecure Agents podcast to talk about Certified Patches, supply chain security, and the future of securing AI agents.
Check out the full episode β
socket.dev/blog/insecur...
08.01.2026 22:42 β π 2 π 1 π¬ 0 π 0
π π "I feel like a fucking idiot for somehow being able to build this CSS framework that's taken over the world and it's used by everything and it's super popular, but I can't figure out how to have it make enough money that eight people can work on it." - @adamwathan.com
08.01.2026 19:51 β π 19 π 6 π¬ 2 π 1
β¨
07.01.2026 23:33 β π 0 π 0 π¬ 0 π 0
npm to Implement Staged Publishing After Turbulent Shift Off...
The planned feature introduces a review step before releases go live, following the Shai-Hulud attacks and a rocky migration off classic tokens that d...
Strongly recommend this post on npmβs staged publishing change after supply-chain turmoil. npm will roll out staged publishing to add a review step before releases go live after the Shai-Hulud attacks, giving maintainers a chance to catch bad releases.
Read it here: socket.dev/blog/npm-to-...
07.01.2026 19:58 β π 4 π 1 π¬ 1 π 0
How GitHub could secure npm - Human Who Codes
Why doesn't npm detect compromised packages the way credit card companies detect fraud?
Must-read from Nicholas C. Zakas (ESLint maintainer) on how GitHub could better secure npm and prevent supply-chain attacks. humanwhocodes.com/blog/2026/01...
07.01.2026 19:55 β π 6 π 1 π¬ 0 π 0
Agree
07.01.2026 18:57 β π 1 π 0 π¬ 0 π 0
Β· @npmjs.bsky.social appears to be massively under-resourced for the scale of the registry it operates. My respect to the teams keeping it running through wave after wave of supply chain attacks.
07.01.2026 18:25 β π 10 π 3 π¬ 1 π 0
π€βοΈ Battle of the Bots:
Dependabot opens a PR. Socket flags it as malicious.
Socket CEO @feross.bsky.social discusses dependency risk and update timing, on @softwaredaily.bsky.social.
Full episode β socket.dev/blog/softwar...
06.01.2026 22:23 β π 8 π 5 π¬ 0 π 0
ποΈ In this episode of @softwaredaily.bsky.social, Socket CEO @feross.bsky.social discusses #OSS maintainer burnout.
βI put this code online as a gift to the world. I didnβt promise it would never have a defect.β
Full episode β socket.dev/blog/softwar... #OpenSource
06.01.2026 18:02 β π 4 π 2 π¬ 0 π 0
Spearphishing Campaign Abuses npm Registry to Target U.S. an...
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, ta...
π¨ New research: A spearphishing campaign published 27 malicious npm packages that host browser-run lures mimicking document portals and Microsoft sign-in to steal credentials. This operation targets manufacturing and healthcare orgs in the U.S. and allied countries.
socket.dev/blog/spearph...
23.12.2025 19:47 β π 5 π 3 π¬ 0 π 1
AWS hero blogging at webdev.rip, building sanity.io, arc.codes and enhance.dev ... loves Nanaimo, Vancouver, programming, JavaScript, cloud functions, infra-as-code, synths, drum machines, and outdoors-y stuff. π¨π¦
JavaScript Infrastructure & Tooling at Bloomberg. Co-chairing TC39. Likely to tweet tech stuff about JS & software performance. Opinions are my own.
Working on supply chain security for JS. LavaMoat and Endo contributor. meet.js Poland organizer. Node.js user since v0.8.
Addicted to teaching.
https://naugtur.pl
My stream-of-consciousness. Father, surfer, husband. Secops by trade, Software Dev by contract and crypto enthusiast in between. Portfolio: BTC, SOL, ETH, XTZ. Stack(s): Ruby On Rails, JavaScript, Redis, Puma, Polygon, React, Postgres. π²π½π΅πΉ Terazco Tribe.
TL;DR
Staff dev @ Shopify
Co-organizer @ ForwardJS Ottawa
Cat mom
Not a morning person
web performance and DevTools, mostly.
In '97 I wrote a paper for English class on HTML Image Maps. I haven't changed much since.
CEO at Render: https://render.com
Music hacker / button pusher / #gamedev #voxelart #webgl // Wellington, NZ
Head of Content Marketing at Socket (socket.dev). Open source and open web advocate, runner, knitter. Find me at sarahgooding.dev
Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS.
https://socket.dev
project lead matrix.org | CEO/CTO Element
π¨π¦ Vancouver
π @katiewilde.com
π’ @inkandswitch.com
ποΈ @ucan.xyz
π° Always learning
π‘ Woke AF
π³οΈβπ Heckin' sapphic
π³οΈββ§οΈ Protect trans kids
β BLM/Land Back/Antifa
π notes.brooklynzelenka.com
π types.pl/@expede
π©πΌβπ» github.com/expede
ποΈ codeberg.org/expede
Node.js TSC β’ Founder Engineer at @vlt.sh β’ Previously Google, GitHub, npm Inc. Opinions are my own.
π Montreal π¨π¦
Back in Chicago as a stay-at-home dad and small business owner. Expect some infosec/privacy/safety, 3D printing, and politics. You're probably following me because of my old job(s).
infosec.exchange/@jschuh
Defunct: twitter.com/justinschuh
Working on finding bad software extensions. More at: https://annex.security
Creator of the infamous Bluesky counting thread
building https://iroh.computer to connect all peers together