Ahmad Nassri's Avatar

Ahmad Nassri

@ahmadnassri.com.bsky.social

Syrian-Canadian πŸ‡ΈπŸ‡ΎπŸ‡¨πŸ‡¦, Fractional CTO, Developer Accelerator. past: npm, Telus, Kong, CBC, BlackBerry

750 Followers  |  44 Following  |  15 Posts  |  Joined: 24.07.2023  |  1.6242

Latest posts by ahmadnassri.com on Bluesky

Post image

πŸš€ Socket Launch Week Day 5!

Malicious packages are infiltrating development environments before they ever reach production.

Today we're answering these threats with the release of Socket Firewall Enterprise: configurable, enterprise-grade protection for modern package ecosystems.

24.10.2025 18:27 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Announcing Experimental Malware Scanning for the Hugging Face Ecosystem
YouTube video by Socket Security Announcing Experimental Malware Scanning for the Hugging Face Ecosystem

1️⃣
AI models aren’t just math -- they’re code.
And just like npm or PyPI, they can get hacked.

Today we’re launching malware scanning for the Hugging Face ecosystem. πŸ€–πŸ”

Socket can now detect backdoors and malicious payloads inside AI models themselves.

πŸ‘‡

www.youtube.com/watch?v=9FQy...

20.10.2025 16:21 β€” πŸ‘ 10    πŸ” 6    πŸ’¬ 2    πŸ“Œ 0

for better security: I use 1password cli with direnv to dynamically load env values (ssh keys, tokens, secrets, etc ...)

AWS outage -> 1password thinks it's offline -> can't run anything locally which requires secretsπŸ₯²

20.10.2025 16:45 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Recognition for Sarah! So deserved! @sarahgooding.bsky.social

16.10.2025 14:50 β€” πŸ‘ 9    πŸ” 4    πŸ’¬ 2    πŸ“Œ 0
Post image

Join me next week at the @workos.bsky.social Enterprise Ready Conf. will be speaking on a panel on all things security & how developers can take back control of their software supply chain.

If you're attending, lchat with me & the @socket.dev team IRL!

enterprise-ready.com

15.10.2025 15:16 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Socket Integrates With Bun 1.3’s Security Scanner API - Sock... Socket now integrates with Bun 1.3’s Security Scanner API to block risky packages at install time and enforce your organization’s policies in local de...

@bun.sh users can now install any package with confidence, knowing that @socket.dev got their back!

Free from malicious packages, typosquatting, and other supply chain attacks.

socket.dev/blog/socket-...

10.10.2025 22:36 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
175 Malicious npm Packages Host Phishing Infrastructure Targ... 175 malicious npm packages (26k+ downloads) used unpkg CDN to host redirect scripts for a credential-phishing campaign targeting 135+ organizations wo...

β†’ 175 malicious packages
β†’ 135+ targeted organizations
β†’ 26,800+ downloads
β†’ Fully automated victim generation
β†’ Pre-filled credential forms
β†’ Complete PyInstaller toolkit included

Technical deep-dive with full IOCs: πŸ‘‰ socket.dev/blog/175-mal...

10.10.2025 12:34 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

AppSec is not just protecting your product/business, it's about protecting everyone!

These packages do nothing malicious to developers/products they infect. Instead, they are targeting web visitors of the infected apps, with the ultimate goal of mass credential harvesting.

10.10.2025 12:34 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
175 Malicious npm Packages Host Phishing Infrastructure Targ... 175 malicious npm packages (26k+ downloads) used unpkg CDN to host redirect scripts for a credential-phishing campaign targeting 135+ organizations wo...

Supply chain attacks are evolving and so should your security practices.

case-in-point: Beamglea - a campaign that turns npm πŸ’” into a phishing-as-a-service platform

This isn't your typical supply chain attack. It's infrastructure weaponization.

socket.dev/blog/175-mal...

10.10.2025 12:34 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Post image

Happy to share I'm getting back to my roots in open source, this time around on the side of protecting software development!

If you haven't yet, you should install @socket.dev for your team!

06.10.2025 21:39 β€” πŸ‘ 16    πŸ” 2    πŸ’¬ 0    πŸ“Œ 1
Post image

🚨 npm phishing alert!
Attackers are sending emails from spoofed support@npmjs.org addresses linking to a typosquatted clone site (npnjs.com) to steal credentials. This attack is designed to hijack npm accounts. Careful with those email links: socket.dev/blog/npm-phi... #nodejs #JavaScript

18.07.2025 20:20 β€” πŸ‘ 21    πŸ” 14    πŸ’¬ 1    πŸ“Œ 1
Post image Post image Post image Post image

get some perspective.

2 million people, surrounded by walls and the sea, under a 17+ year blockade.

what if it was in your city?

#GazaAttack #Gaza #GazaEverywhere

ahmadnassri.github.io/gaza-everywh...

16.10.2023 15:51 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

what's with the recent explosion of PMP certification spam on LinkedIn ????

18.08.2023 14:13 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Ask a CTO - Building your technology investment strategy August 10, 2023

I'm starting to document some of my fundamental learnings in this industry in writing ... took a first stab at some of it in a guesr post at Unified's blog (disclaimer: I'm an advisor)

next post will be about TCO & MVP architecture needs for startups

10.08.2023 20:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

note: those existed in non-fractional roles as well, but I saw those as my ownership to fix / address, and for the most part, I managed to resolve ~80% of the time

26.07.2023 12:08 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

the staggering amount of over-engineering, horrible leadership, and clueles product owners I've seen after ~3 years of being a Fractional CTO really makes me question this entire career / industry...

if I had to do it all over again, I'd probably go into banking or law ...

26.07.2023 12:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

dev++ 🧠: write a custom TF module to group & manage domains with a yaml data source that shares reusable configs

25.07.2023 17:21 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

normal 🧠: need to update a single DNS record for my domain

dev 🧠: now is the right time to migrate 50+ domains from Google Domains to CloudFlare AND do a full Terraform automation pipeline on GH Actions to manage them all!

25.07.2023 17:20 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

I AM HERE!

24.07.2023 20:52 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@ahmadnassri.com is following 20 prominent accounts