 
                                                
    
    
    
    
            π Socket Launch Week Day 5!
Malicious packages are infiltrating development environments before they ever reach production.
Today we're answering these threats with the release of Socket Firewall Enterprise: configurable, enterprise-grade protection for modern package ecosystems.
               
            
            
                24.10.2025 18:27 β π 2    π 1    π¬ 1    π 0                      
            
         
            
        
            
            
            
            
            
    
    
            
            
            
                YouTube video by Socket Security
                Announcing Experimental Malware Scanning for the Hugging Face Ecosystem
            
         
    
    
            1οΈβ£
AI models arenβt just math -- theyβre code.
And just like npm or PyPI, they can get hacked.
Today weβre launching malware scanning for the Hugging Face ecosystem. π€π
Socket can now detect backdoors and malicious payloads inside AI models themselves.
π
www.youtube.com/watch?v=9FQy...
               
            
            
                20.10.2025 16:21 β π 10    π 6    π¬ 2    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            for better security: I use 1password cli with direnv to dynamically load env values (ssh keys, tokens, secrets, etc ...)
AWS outage -> 1password thinks it's offline -> can't run anything locally which requires secretsπ₯²
               
            
            
                20.10.2025 16:45 β π 1    π 0    π¬ 1    π 0                      
            
         
            
        
            
            
            
            
                                                 
                                                
    
    
    
    
            Recognition for Sarah! So deserved! @sarahgooding.bsky.social
               
            
            
                16.10.2025 14:50 β π 9    π 4    π¬ 2    π 0                      
            
         
            
        
            
            
            
            
                                                 
                                                
    
    
    
    
            Join me next week at the @workos.bsky.social Enterprise Ready Conf. will be speaking on a panel on all things security & how developers can take back control of their software supply chain.
If you're attending,  lchat with me & the @socket.dev team IRL!
enterprise-ready.com
               
            
            
                15.10.2025 15:16 β π 1    π 1    π¬ 0    π 0                      
            
         
            
        
            
        
            
            
            
            
            
    
    
            
                             
                        
                175 Malicious npm Packages Host Phishing Infrastructure Targ...
                175 malicious npm packages (26k+ downloads) used unpkg CDN to host redirect scripts for a credential-phishing campaign targeting 135+ organizations wo...
            
        
    
    
            β 175 malicious packages 
β 135+ targeted organizations
β 26,800+ downloads 
β Fully automated victim generation 
β Pre-filled credential forms 
β Complete PyInstaller toolkit included
Technical deep-dive with full IOCs: π socket.dev/blog/175-mal...
               
            
            
                10.10.2025 12:34 β π 1    π 0    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            AppSec is not just protecting your product/business, it's about protecting everyone!
These packages do nothing malicious to developers/products they infect. Instead, they are targeting web visitors of the infected apps, with the ultimate goal of mass credential harvesting.
               
            
            
                10.10.2025 12:34 β π 2    π 1    π¬ 1    π 0                      
            
         
            
        
            
            
            
            
            
    
    
            
                             
                        
                175 Malicious npm Packages Host Phishing Infrastructure Targ...
                175 malicious npm packages (26k+ downloads) used unpkg CDN to host redirect scripts for a credential-phishing campaign targeting 135+ organizations wo...
            
        
    
    
            Supply chain attacks are evolving and so should your security practices.
case-in-point: Beamglea - a campaign that turns npm π into a phishing-as-a-service platform
This isn't your typical supply chain attack. It's infrastructure weaponization.
socket.dev/blog/175-mal...
               
            
            
                10.10.2025 12:34 β π 4    π 1    π¬ 1    π 0                      
            
         
            
        
            
            
            
            
                                                 
                                                
    
    
    
    
            Happy to share I'm getting back to my roots in open source, this time around on the side of protecting software development!
If you haven't yet, you should install @socket.dev for your team!
               
            
            
                06.10.2025 21:39 β π 16    π 2    π¬ 0    π 1                      
            
         
            
        
            
            
            
            
                                                 
                                                
    
    
    
    
            π¨ npm phishing alert! 
Attackers are sending emails from spoofed support@npmjs.org addresses linking to a typosquatted clone site (npnjs.com) to steal credentials. This attack is designed to hijack npm accounts. Careful with those email links: socket.dev/blog/npm-phi... #nodejs #JavaScript
               
            
            
                18.07.2025 20:20 β π 21    π 14    π¬ 1    π 1                      
            
         
            
        
            
        
            
            
            
            
            
    
    
    
    
            what's with the recent explosion of PMP certification spam on LinkedIn ????
               
            
            
                18.08.2023 14:13 β π 1    π 0    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
            
                        
                Ask a CTO - Building your technology investment strategy
                August 10, 2023
            
        
    
    
            I'm starting to document some of my fundamental learnings in this industry in writing ... took a first stab at some of it in a guesr post at Unified's blog (disclaimer: I'm an advisor)
next post will be about TCO & MVP architecture needs for startups
               
            
            
                10.08.2023 20:34 β π 0    π 0    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            note: those existed in non-fractional roles as well, but I saw those as my ownership to fix / address, and for the most part, I managed to resolve ~80% of the time
               
            
            
                26.07.2023 12:08 β π 0    π 0    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            the staggering amount of over-engineering, horrible leadership, and clueles product owners I've seen after ~3 years of being a Fractional CTO really makes me question this entire career / industry...
if I had to do it all over again, I'd probably go into banking or law ...
               
            
            
                26.07.2023 12:06 β π 0    π 0    π¬ 1    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            dev++ π§ : write a custom TF module to group & manage domains with a yaml data source that shares reusable configs
               
            
            
                25.07.2023 17:21 β π 0    π 0    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            normal π§ : need to update a single DNS record for my domain
dev π§ : now is the right time to migrate 50+ domains from Google Domains to CloudFlare AND do a full Terraform automation pipeline on GH Actions to manage them all!
               
            
            
                25.07.2023 17:20 β π 0    π 0    π¬ 1    π 0                      
            
         
            
        
            
            
            
            
                                                 
                                                
    
    
    
    
            I AM HERE!
               
            
            
                24.07.2023 20:52 β π 3    π 0    π¬ 0    π 0                      
            
         
    
         
        
            
        
                            
                    
                    
                                            tafka @kuvos
eng @socket.dev
- 15yr js/ts
- rust
- ex vercel
- ex fb
- js1k-guy
                                     
                            
                    
                    
                                            Lodash creator β’ sometimes TC39 delegate β’ protecting supply chains at https://Socket.dev β’ Ex (Bun, Salesforce, Node core, Electron WG, Microsoft)
                                     
                            
                    
                    
                                            π§ββοΈ Mad scientist β’ β¨ Founder + CEO @Socket.dev (http://socket.dev) β’π² Stanford lecturer (http://cs253.stanford.edu) β’ β€οΈ Open source at WebTorrent + StandardJS
                                     
                            
                    
                    
                                            Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. 
https://socket.dev
                                     
                            
                            
                    
                    
                                            Opinions my own.
https://sarah.dev
Sr Director of Engineering @ Google: Core Web, Android, iOS Infrastructure
Formerly Vue Core β’
Frontend Masters teacher β’
O'Reilly Author β’ 
https://www.engmanagement.dev/
https://github.com/sdras
                                     
                            
                    
                    
                                            Developer of sorts at @firefox.com. No thought goes unpublished. He/him.
                                     
                            
                    
                    
                                            π A simpler static site generator
π https://www.11ty.dev/
π Created/maintained by @zachleat.com (this account, too)
π¦ Team HTML/Jamstack
π€ Team @fontawesome.com
π Mastodon https://neighborhood.11ty.dev/@11ty
                                     
                            
                    
                    
                                            Low key finance high key drunkenness 
                                     
                            
                            
                    
                    
                                            Developing software one mistake at a time. LEGO obsessed.
                                     
                            
                            
                    
                    
                                            Making the web more stylish β¨π¨ DevRel Lead for CSS & Web UI @ Google Chrome. Cohost of the CSS Podcast & host of Designing in the Browser. π una.im 
                                     
                            
                    
                    
                                            Executive Director at OpenJS Foundation
amateur drummer 
she/her
                                     
                            
                    
                    
                                            β¨ Node.js core contributorβ¨π€ Node.js diagnostics working group founderβ¨π οΈ V8 contributorβ¨π Compiler and language design nerdβ¨β€οΈ Powered by kindnessβ¨π¨π»βπ» Principal Software Engineer at Platformaticβ¨π¨π¦ Living in Vancouver/Manila/Valencia
                                     
                            
                    
                    
                                            he/him πͺπΊπ¦πΉ JavaScript Infrastructure & Tooling at Bloomberg. TC39/Temporal. Humanist Human. Opinions are always my own.
                                     
                            
                    
                    
                                            Founder of https://universe.app β Affordable campaign tools for progressive, down-ballot candidates.
Prev: Design Systems @LinkedIn, ⬑.js CommComm Chair, Plain View Project, CSS Blocks co-creator He/Him
                                     
                            
                    
                    
                                            Staff Software Engineer - Datadog APM
(he/him/his)
Dad
Royal Oak, MI
https://bryanenglish.com
                                     
                            
                    
                    
                                            Trying to make a web that works for everyone.
Also at https://toot.cafe/@slightlyoff
For more: https://infrequently.org/about-me/
https://infrequently.org/
                                     
                            
                    
                    
                                            Node.js TSC β’ Founder Engineer at @vlt.sh β’ Previously Google, GitHub, npm Inc. Opinions are my own.
π Montreal π¨π¦