Sarah Gooding's Avatar

Sarah Gooding

@sarahgooding.bsky.social

Head of Content Marketing at Socket (socket.dev). Open source advocate, runner, knitter. Find me at sarahgooding.dev

400 Followers  |  129 Following  |  126 Posts  |  Joined: 06.07.2023  |  2.2957

Latest posts by sarahgooding.bsky.social on Bluesky

Video thumbnail

IDE extensions are a silent nightmare.

VS Code extensions get full access to your code and creds, and attackers have already slipped malware into VS Code Marketplace and OpenVSX.

So Socket now scans OpenVSX extensions before they ever hit your machine. πŸ”βš‘οΈ

20.11.2025 17:39 β€” πŸ‘ 6    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0
Video thumbnail

πŸš€ Big news for JavaScript teams: Socket now supports Bun and vlt in beta.

You no longer have to choose between innovation and security. Commit a bun.lock or vlt-lock.json and Socket gives you full supply chain protection.

19.11.2025 17:21 β€” πŸ‘ 9    πŸ” 5    πŸ’¬ 1    πŸ“Œ 0

This is a novel technique attackers are using to distribute browser-executed malware through npm.

cc: @campuscodi.risky.biz

19.11.2025 03:20 β€” πŸ‘ 7    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0

I had the pleasure of being on-call for a lot of what Elizabeth talked about on this (love is blind & the Tyson fight). It's fun to hear such a polished, clear, and positive message about the absolute *madness* (aka fun) it was to be involved as an engineer on the ground.

12.11.2025 22:39 β€” πŸ‘ 6    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

New research from @socket.dev: a malicious Chrome extension posing as an Ethereum wallet steals seed phrases by encoding them into Sui transactions. Wild on-chain exfiltration technique. Still live on the Chrome Web Store.

cc: @campuscodi.risky.biz

13.11.2025 02:55 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Thrilled to have Jordan joining us at @socket.dev! πŸ’œ

06.11.2025 21:42 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

This is wild. 99% of the code is legit, with just 20 malicious lines buried in thousands of lines of working code.

cc: @campuscodi.risky.biz

06.11.2025 21:41 β€” πŸ‘ 10    πŸ” 6    πŸ’¬ 0    πŸ“Œ 0
Preview
The Changelog Podcast: Practical Steps to Stay Safe on npm -... Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.

Five practical steps to stay safe on npm
@sarahgooding.bsky.social @socket.dev
socket.dev/blog/the-cha...

#ECMAScript #JavaScript

03.11.2025 18:53 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

‼️ Update: the MIT-linked β€œAI-powered ransomware” report appears to have been taken offline. We updated our article to include an Internet Archive link to the original paper.

01.11.2025 04:00 β€” πŸ‘ 25    πŸ” 11    πŸ’¬ 3    πŸ“Œ 0
Preview
The Changelog Podcast: Practical Steps to Stay Safe on npm -... Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.

Still installing npm packages like it’s 2020? Not all npm installs are treats. πŸŽƒ

On the @changelog.com podcast, @feross.bsky.social shares practical steps every developer should take to reduce exposure to supply chain attacks on npm. β†’

socket.dev/blog/the-cha... #NodeJS #JavaScript

31.10.2025 18:46 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

Thanks Cynthia! I tried but didn't see your DMs open.

31.10.2025 17:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

That MIT report is absolutely bonkers btw - it classifies 80% of ransomware groups as using GenAI (made up btw), then says things like Emotet uses AI (what? It’s a banking trojan from years ago), Ryuk uses AI (?!?!) etc etc.

And it’s published via MIT with their chief security persons name on it.

31.10.2025 11:36 β€” πŸ‘ 44    πŸ” 8    πŸ’¬ 6    πŸ“Œ 1

This is really well written, if you want to scare your CISO, send them this for Halloween. πŸŽƒ

31.10.2025 11:32 β€” πŸ‘ 59    πŸ” 16    πŸ’¬ 1    πŸ“Œ 1

There’s a real conversation to be had about how AI has found real-world use cases across cybercrime, but there’s no way in heck that β€œ80 percent of ransomware attacks are AI-driven,” as this report claims. πŸ€‘
h/t @doublepulsar.com

cc: @campuscodi.risky.biz

31.10.2025 02:03 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Some fairly convincing typosquats in this campaign - a reminder that typosquatting is still an effective attack vector on npm.

cc: @campuscodi.risky.biz

29.10.2025 02:49 β€” πŸ‘ 4    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

This is a wild typosquat hiding #NuGet malware:
cc: @campuscodi.risky.biz

22.10.2025 04:20 β€” πŸ‘ 4    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Post image

Can you believe it – we’re kicking off another Socket Launch Week! πŸŽ‰ We'll be announcing a new feature every day.

And we’re starting big: Today we're introducing malware scanning for the Hugging Face ecosystem! #HuggingFace

20.10.2025 17:42 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

Wow! I'm honored to receive this award from the @openjsf.org. It's a privilege to share stories that highlight the people and projects driving open source security forward. I'm thankful my work at @socket.dev lets me support the OSS maintainers and users at the heart of this community. πŸ’œ

16.10.2025 16:08 β€” πŸ‘ 10    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

More malicious packages linked to North Korea, leveraging typosquatting.

Targets include Web3, cryptocurrency, and blockchain developers, as well as technical job seekers approached with recruiting lures, leading to multi-stage compromise and financial loss.

cc: @campuscodi.risky.biz

15.10.2025 01:17 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Ruby Central’s incident report on the RubyGems.org access dispute sparks community backlash and renewed debate over project governance.

An overview on the latest news from the Ruby gems packaging ecosystem with comments from @indirect.io and @duckinator.bsky.social:

15.10.2025 00:25 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Big change in Google’s OSV that hasn’t gotten much attention: 500+ advisories just reappeared after a policy fix that had been hiding disputed CVEs.

cc: @campuscodi.risky.biz

10.10.2025 04:01 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
Introducing Socket Firewall: Free, Proactive Protection for ... Socket Firewall is a free tool that blocks malicious packages at install time, giving developers proactive protection against rising supply chain atta...

Introducing Socket Firewall: free, proactive protection for your software supply chain
@dale.link @socket.dev
socket.dev/blog/introdu...

#ECMAScript #JavaScript

07.10.2025 02:22 β€” πŸ‘ 8    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0

Thrilled to have @ahmadnassri.com joining us at Socket! πŸŽ‰πŸŽ‰πŸŽ‰

07.10.2025 01:28 β€” πŸ‘ 6    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Gem Cooperative Emerges as a Community-Run Alternative to Ru... Former RubyGems maintainers have launched The Gem Cooperative, a new community-run project aimed at rebuilding open governance in the Ruby ecosystem.

πŸ”₯ Breaking: Former #RubyGems maintainers have launched the Gem Cooperative, a community-run RubyGems server with open governance.

We spoke with the team behind it. Read the full story on the Socket blog
→ socket.dev/blog/gem-coo... #RubyLang #Ruby #Rails

06.10.2025 04:28 β€” πŸ‘ 8    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

This week we released Socket Firewall, a free CLI tool that protects developers from malicious packages at install time. We're excited to extend protection beyond npm to other ecosystems like #Python and #Rust, with more rolling out soon!

@thisweekinrust.bsky.social @campuscodi.risky.biz
#rustlang

03.10.2025 02:59 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Excited to see The Register cover the launch of Socket Firewall!

This new free tool gives developers real-time protection at install time across multiple ecosystems, including JavaScript, Python, and Rust, with more coming soon. It works out of the box: No API key. No configuration.

01.10.2025 13:52 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Other than the trusted publishing stuff (which is absolutely not ready for use yet, I will be outlining why in my JS Conf talk) this is a great write up of the recent goings on.

01.10.2025 02:36 β€” πŸ‘ 11    πŸ” 5    πŸ’¬ 2    πŸ“Œ 0
Post image

⚑️ Follow Socket on Instagram! www.instagram.com/socketsecuri...

19.09.2025 10:49 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

…what a time to be in the JavaScript web security space…

16.09.2025 21:44 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
Ongoing Supply Chain Attack Targets CrowdStrike npm Packages... Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Halud" supply chain attack that previously hit Tinycolor and dozen...

🚨 Update: The "Shai-Hulud" supply chain attack has expanded to nearly 500 trojanized npm packages, including several from CrowdStrike, all using the same malware first seen in Tinycolor.

Full details and package list: socket.dev/blog/ongoing... #NodeJS #JavaScript

16.09.2025 18:15 β€” πŸ‘ 31    πŸ” 15    πŸ’¬ 1    πŸ“Œ 5

@sarahgooding is following 20 prominent accounts