Blocking Software Supply Chain Attacks with Feross Aboukhadijeh
Modern software relies heavily on open source dependencies, often pulling in thousands of packages maintained by developers all over the world. This accelerates innovation but also creates serious supply chain risks as attackers increasingly compromise popular libraries to spread malware at scale.
Feross Aboukhadijeh is the founder and CEO of Socket which is a security platform designed to protect software projects from open source supply chain attacks. In this episode he joins Josh Goldberg to talk about his career in open source, open source supply chain attacks, practical security lessons, the expanding attack surface in software development, and more.
Josh Goldberg is an independent full time open source developer in the TypeScript ecosystem. He works on projects that help developers write better TypeScript more easily, most notably on typescript-eslint: the tooling that enables ESLint and Prettier to run on TypeScript code. Josh regularly contributes to open source projects in the ecosystem such as ESLint and TypeScript. Josh is a Microsoft MVP for developer technologies and the author of the acclaimed Learning TypeScript (O’Reilly), a cherished resource for any developer seeking to learn TypeScript without any prior experience outside of JavaScript. Josh regularly presents talks and workshops at bootcamps, conferences, and meetups to share knowledge on TypeScript, static analysis, open source, and general frontend and web development.
Please click here to see the transcript of this episode.
Sponsorship inquiries: sponsor@softwareengineeringdaily.com
The post Blocking Software Supply Chain Attacks with Feross Aboukhadijeh appeared first on Software Engineering Daily.
npm under siege (what to do about it) (Friends)
Over the past two months, we’ve seen some of the most serious supply chain attacks in npm history: phishing campaigns, maintainer account takeovers, and malware published to packages with billions of weekly downloads. What is going on?! What can we do about it? Our old friend, Feross Aboukhadijeh, joins us to help make sense of it all.
Join the discussion
Changelog++ members save 2 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
Depot – 10x faster builds? Yes please. Build faster. Waste less time. Accelerate Docker image builds, and GitHub Actions workflows. Easily integrate with your existing CI provider and dev workflows to save hours of build time.
Featuring:
Feross Aboukhadijeh – Website, GitHub, X
Jerod Santo – Website, GitHub, LinkedIn, Mastodon, X
Adam Stacoviak – Website, GitHub, LinkedIn, Mastodon, X
Show Notes:
Active supply chain attack: npm phishing campaign
Npm phishing email targets developers with typosquat
Nx npm packages compromised in supply chain attack
Introducing socket firewall
Changelog News Classifieds
Something missing or broken? PRs welcome!
Risky Business #806 -- Apple's Memory Integrity Enforcement is a big deal
On this week’s show Patrick Gray and Adam Boileau discuss the week’s cybersecurity news, including:
Apple ruins exploit developers’ week with fresh memory corruption mitigations
Feross Aboukhadijeh drops by to talk about the big, dumb npm supply chain attack
Salesloft says its GitHub was the initial entry point for its compromise
Sitecore says people should “patch” its using-the-keymat-from-the-documentation “zero day”
Rogue certs for 1.1.1.1 appear to be just (stupid) testing
Jaguar Land Rover ransomware attackers are courting trouble
This week’s episode is sponsored by open source cloud security tool, Prowler. Founder Toni de la Fuente joins to discuss their new support for Microsoft 365. Time to point Prowler at your OneDrive and Sharepoint!
This episode is also available on Youtube.
Show notes
Blog - Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research
Venezuela's president thinks American spies can't hack Huawei phones | TechCrunch
18 Popular Code Packages Hacked, Rigged to Steal Crypto – Krebs on Security
Software packages with more than 2 billion weekly downloads hit in supply-chain attack - Ars Technica
Salesloft platform integration restored after probe reveals monthslong GitHub account compromise | Cybersecurity Dive
CISA orders federal agencies to patch Sitecore zero-day following hacking reports | The Record from Recorded Future News
SAP warns of high-severity vulnerabilities in multiple products - Ars Technica
The number of mis-issued 1.1.1.1 certificates grows. Here’s the latest. - Ars Technica
Cyberattack on Jaguar Land Rover threatens to hit British economic growth | The Record from Recorded Future News
Cyberattack forces Jaguar Land Rover to tell staff to stay at home | The Record from Recorded Future News
Bridgestone Americas continues probe as it looks to restore operations | Cybersecurity Dive
Qantas penalizes executives for July cyberattack | The Record from Recorded Future News
Cyber Command, NSA to remain under single leader as officials shelve plan to end 'dual hat' | The Record from Recorded Future News
GOP Cries Censorship Over Spam Filters That Work – Krebs on Security
Risky Bulletin: APT report? No, just a phishing test! - Risky Business Media
Post by @patrick.risky.biz — Bluesky
Risky Biz Soap Box: How to measure vulnerability reachability
In this Soap Box edition of the Risky Business podcast Patrick Gray chats with Socket founder Feross Aboukhadijeh about how to measure the reachability of vulnerabilities in applications.
It’s great to know there’s a CVE in a library you’re using, but it’s even better if you can say whether or not that vulnerability actually impacts your application.
They also talk about how Socket started out as a way to discover malicious packages in software projects, but these days it’s playing the CVE game as well.
This episode is also available on Youtube.
Show notes
Cybersecurity's Past, Present, and AI-Driven Future
Is it time to hand over cybersecurity to machines amidst the exponential rise in cyber threats and breaches?
We trace the evolution of cybersecurity from minimal measures in 1995 to today's overwhelmed DevSecOps. Travis McPeak, CEO and Co-founder of Resourcely, kicks off our discussion by discussing the historical shifts in the industry. Kevin Tian, CEO and Founder of Doppel, highlights the rise of AI-driven threats and deepfake campaigns. Feross Aboukhadijeh, CEO and Founder of Socket, provides insights into sophisticated attacks like the XZ Utils incident. Andrej Safundzic, CEO and Founder of Lumos, discusses the future of autonomous security systems and their impact on startups.
Recorded at a16z's Campfire Sessions, these top security experts share the real challenges they face and emphasize the need for a new approach.
Resources:
Find Travis McPeak on Twitter: https://x.com/travismcpeak
Find Kevin Tian on Twitter: https://twitter.com/kevintian00
Find Feross Aboukhadijeh on Twitter: https://x.com/feross
Find Andrej Safundzic on Twitter: https://x.com/andrejsafundzic
Stay Updated:
Find a16z on Twitter: https://twitter.com/a16z
Find a16z on LinkedIn: https://www.linkedin.com/company/a16z
Subscribe on your favorite podcast app: https://a16z.simplecast.com/
Follow our host: https://twitter.com/stephsmithio
Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures.
Stay Updated:
Find a16z on YouTube: YouTube
Find a16z on X
Find a16z on LinkedIn
Listen to the a16z Show on Spotify
Listen to the a16z Show on Apple Podcasts
Follow our host: https://twitter.com/eriktorenberg
Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures.
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
705: Is Running Random Code From npm Safe? With Feross Aboukhadijeh
In this Supper Club episode of Syntax, Wes and Scott talk with Feross Aboukhadijeh about his work on Socket which helps to make sure the code you get from npm is safe and secure. They also touch on his work on Wormhole and Web Torrent.
Show Notes
00:30 Welcome
00:57 Who is Feross Aboukhadijeh?
01:33 What is Socket?
[Socket.dev](https://socket.dev
dominictarr (Dominic Tarr)
pull-stream/pull-stream: minimal streams
03:59 Introducing AI package summaries
Example of the AI summaries
Introducing AI Package Summaries
07:04 Is Socket’s focus on visibility of a open source project?
10:01 What was the inspiration for Socket?
Introducing “safe npm”, a Socket npm Wrapper - Socket
16:22 How does Socket detect possible security issues?
Removed packages
event-source-polyfill protestware attack
john wick spam attack
18:55 How many projects are you injesting for Socket to scan?
26:00 What kinds of things are people trying to inject in code?
CS253 Web Security
29:54 How do I hook Socket up to my project or GitHub?
32:08 Do we still need to use shrink wrap?
36:34 How did you implement the torrent spec in JavaScript for WebTorrent?
WebTorrent Desktop
WebTorrent FAQ
43:11 Why did you build Wormhole?
Wormhole
47:33 How expensive is it to maintain Wormhole?
Riverside.fm - Record Podcasts And Videos From Anywhere
50:37 What do you think of decentralized code repos?
Radicle
Project Fugu
Fugu Tracker
54:29 Understanding passkeys
56:15 Supper Club questions
GitHub Theme - Visual Studio Marketplace
Web Serial API - Web APIs | MDN
01:03:04 Sick Picks
Sick Picks Harry Potter audio books
Shameless Plugs ChatGPT
Hit us up on Socials! Syntax: X Instagram Tiktok LinkedIn Threads
Wes: X Instagram Tiktok LinkedIn Threads
Scott: X Instagram Tiktok LinkedIn Threads
Making "safe npm"
Feross and his team at Socket recently shipped a wrapper library for the ubiquitous npm package manager’s command-line interface that brings enhanced security when you need it most: before executing any code
Bradly Farias lead this effort, so Jerod & Chris invited him on the show to learn all about it.
Join the discussion
Changelog++ members save 3 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
Fastly – Our bandwidth partner. Fastly powers fast, secure, and scalable digital experiences. Move beyond your content delivery network to their powerful edge cloud platform. Learn more at fastly.com
Fly.io – The home of Changelog.com — Deploy your apps and databases close to your users. In minutes you can run your Ruby, Go, Node, Deno, Python, or Elixir app (and databases!) all over the world. No ops required. Learn more at fly.io/changelog and check out the speedrun in their docs.
Changelog News – A podcast+newsletter combo that’s brief, entertaining & always on-point. Subscribe today.
KBall Coaching – Free exploratory coaching sessions from JS Party co-host KBall! Click here to get started
Featuring:
Bradley Meck Farias – GitHub, LinkedIn, Mastodon, X
Jerod Santo – GitHub, LinkedIn, Mastodon, X
Feross Aboukhadijeh – Website, GitHub, X
Christopher Hiller – Website, GitHub, Mastodon, X
Show Notes:
Introducing “safe npm”
Source code on GitHub
Something missing or broken? PRs welcome!
JS logging & error handling
Nick and Chris welcome back Mik and Bret to discuss logging and error handling in Node and JavaScript and the subtleties and intricacies that extend far beyond console.log!
Join the discussion
Changelog++ members save 4 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
Square – Develop on the platform that sellers trust. There is a massive opportunity for developers to support Square sellers by building apps for today’s business needs. Learn more at changelog.com/square to dive into the docs, APIs, SDKs and to create your Square Developer account — tell them Changelog sent you.
Raygun – Never miss another mission-critical issue again — Raygun Alerting is now available for Crash Reporting and Real User Monitoring, to make sure you are quickly notified of the errors, crashes, and front-end performance issues that matter most to you and your business. Set thresholds for your alert based on an increase in error count, a spike in load time, or new issues introduced in the latest deployment. Start your free 14-day trial at Raygun.com
Ship It! – A podcast about getting your best ideas into the world and seeing what happens. Listen to an episode that interests you and subscribe today.
Featuring:
Bret Comnes – Website, GitHub, X
Mikola Lysenko – GitHub, X
Nick Nisi – Website, GitHub, Mastodon, X
Christopher Hiller – Website, GitHub, Mastodon, X
Show Notes:
JS Party #219 - Making moves on supply chain security
FullStory
pino
grafana
DataDog RUM
React Suspense: Async Rendering in React
Matomo
Abort Signal
Semaphore
Something missing or broken? PRs welcome!
Making moves on supply chain security
Feross has been working on something big. He joins Chris and Nick, along with guests Bret Comnes and Mik Lysenko to discuss Socket, what it is, and its focus on the security of the JavaScript supply chain.
Join the discussion
Changelog++ members save 5 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
Raygun – Never miss another mission-critical issue again — Raygun Alerting is now available for Crash Reporting and Real User Monitoring, to make sure you are quickly notified of the errors, crashes, and front-end performance issues that matter most to you and your business. Set thresholds for your alert based on an increase in error count, a spike in load time, or new issues introduced in the latest deployment. Start your free 14-day trial at Raygun.com
Square – Develop on the platform that sellers trust. There is a massive opportunity for developers to support Square sellers by building apps for today’s business needs. Learn more at changelog.com/square to dive into the docs, APIs, SDKs and to create your Square Developer account — tell them Changelog sent you.
Sourcegraph – Move fast, even in big codebases. Sourcegraph is universal code search for every developer and team. Easily search across all the code that matters to you and your organization: find example code, explore and read code, debug issues, and more. Head to info.sourcegraph.com/changelog and click the button “Try Sourcegraph now” to get started.
SignalWire – Build what’s next in communications with video, voice, and messaging APIs powered by elastic cloud infrastructure. Try it today at signalwire.com/video and mention “Go Time” to receive an extra 5,000 video minutes.
Featuring:
Bret Comnes – Website, GitHub, X
Mikola Lysenko – GitHub, X
Nick Nisi – Website, GitHub, Mastodon, X
Christopher Hiller – Website, GitHub, Mastodon, X
Feross Aboukhadijeh – Website, GitHub, X
Show Notes:
0 FPS
Changelog #482 - Securing the open source supply chain
Socket
React on Socket
npm audit
Lighthouse
peacenotwar supply chain attack
If you’re writing your first npm package: I highly recommend keeping it
Something missing or broken? PRs welcome!
Securing the open source supply chain (Interview)
This week we’re joined by the “mad scientist” himself, Feross Aboukhadijeh…and we’re talking about the launch of Socket — the next big thing in the fight to secure and protect the open source supply chain.
While working on the frontlines of open source, Feross and team have witnessed firsthand how supply chain attacks have swept across the software community and have damaged the trust in open source. Socket turns the problem of securing open source software on its head, and asks…“What if we assume all open source may be malicious?” So, they built a system that proactively detects indicators of compromised open source packages and brings awareness to teams in real-time. We cover the whys, the hows, and what’s next for this ambitious and very much needed project.
Join the discussion
Changelog++ members get a bonus 10 minutes at the end of this episode and zero ads. Join today!
Sponsors:
Sentry – Working code means happy customers. That’s exactly why teams choose Sentry. From error tracking to performance monitoring, Sentry helps teams see what actually matters, resolve problems quicker, and learn continuously about their applications - from the frontend to the backend. Use the code CHANGELOG and get the team plan free for three months.
Square – Develop on the platform that sellers trust. There is a massive opportunity for developers to support Square sellers by building apps for today’s business needs. Learn more at developer.squareup.com to dive into the docs, APIs, SDKs and to create your Square Developer account — tell them Changelog sent you.
Retool – Retool is a low-code platform built specifically for developers that makes it fast and easy to build internal tools. Instead of building internal tools from scratch, the world’s best teams, from startups to Fortune 500s, are using Retool to power their internal apps. Learn more and try it for free at retool.com/changelog
WorkOS – A platform that gives developers a set of building blocks for quickly adding enterprise-ready features to their application. Add Single Sign-On (Okta, Azure, Google, Microsoft OAuth), sync users from any SCIM directory, HRIS integration, audit trails (SIEM), free magic link sign-in. WorkOS is designed for developers and offers a single, elegant interface that abstracts dozens of enterprise integrations. Learn more and get started at WorkOS.com
Featuring:
Feross Aboukhadijeh – Website, GitHub, X
Adam Stacoviak – Website, GitHub, LinkedIn, Mastodon, X
Jerod Santo – Website, GitHub, LinkedIn, Mastodon, X
Show Notes:
Socket.dev
socket.dev/npm/issue
socket.dev/npm/lists/removed
socket.dev/npm/package/left-pad
socket.dev/npm/package/umbrellajs
socket.dev/npm/package/airbnb-fejax
Dev corrupts NPM libs ‘colors’ and ‘faker’ breaking thousands of apps
Popular ‘coa’ NPM library hijacked to steal user passwords
Popular NPM package UA-Parser-JS poisoned with cryptomining, password-stealing malware
Vulnerabilities in NPM allowed threat actors to publish new version of any package
cve.org
browserslist.dev
The Changelog #227: Mad science, WebTorrent, WebRTC with Feross Aboukhadijeh
The Changelog #326: The insider perspective on the event-stream compromise with Dominic Tarr
JS Party #185: Into the Wormhole with Feross Aboukhadijeh
JS Party #210: What’s in your package.json? with Tobie Langel
Something missing or broken? PRs welcome!
Into the Wormhole
Feross is back with a brand new web app for us to pick apart! Wormhole is the fastest way to send files on the internet and we want to know why he built it, how it works, and what crazy hacks he invented along the way.
Join the discussion
Changelog++ members get a bonus 24 minutes at the end of this episode and zero ads. Join today!
Sponsors:
Raygun – With Raygun Error and Performance Monitoring you have all the information you need at your fingertips to quickly find and fix errors and performance issues across your tech stack down to the line of code. Get started with a free 14-day trial, head to raygun.com and join thousands of customer-centric software teams who use Raygun every day.
Micro – Micro is reimagining the cloud for the next generation of developers. It’s a developer friendly platform to explore, search, and use simpler APIs for everyday consumption all in one place. They’re in early development building out the first set of APIs, and they’re looking for feedback from developers. Signup and get $5 in free credits.
Square – Develop on the platform that sellers trust! Use API Explorer to interact with, test, or play with your applications in Square. You can build, view, and send HTTP requests that call Square APIs with API Explorer. Get started with Square, check out the API Explorer, or the API Explorer docs.
Featuring:
Feross Aboukhadijeh – Website, GitHub, X
Jerod Santo – GitHub, LinkedIn, Mastodon, X
Nick Nisi – Website, GitHub, Mastodon, X
Adam Stacoviak – Website, GitHub, LinkedIn, Mastodon, X
Show Notes:
Wormhole
Wormhole Security
Why some developers are avoiding app store headaches by going web-only
Wormhole encrypted file transfer app reboots Firefox Send after Mozilla fled
SocketDev/wormhole-crypto
Socket.dev
Something missing or broken? PRs welcome!
Maintainer spotlight! Feross Aboukhadijeh (Interview)
In this episode we’re shining our maintainer spotlight on Feross Aboukhadijeh. Feross is the creator and maintainer of 100’s of open source projects which have been downloaded 100’s of million of times each month — projects like StandardJS, BitMidi, and WebTorrent to name a few. This episode with Feross continues our maintainer spotlight series where we dig deep into the life of an open source software maintainer. We’re producing this series in partnership with Tidelift. Huge thanks to Tidelift for making this series possible.
Join the discussion
Changelog++ members support our work, get closer to the metal, and make the ads disappear. Join today!
Sponsors:
Tidelift – Tidelift is the first managed open source subscription that pays the maintainers of the exact open source projects you depend on while giving you the commercial support you’ve been looking for. Learn more at tidelift.com.
Featuring:
Feross Aboukhadijeh – Website, GitHub, X
Adam Stacoviak – Website, GitHub, LinkedIn, Mastodon, X
Jerod Santo – Website, GitHub, LinkedIn, Mastodon, X
Show Notes:
JavaScript Standard Style
BitMidi
WebTorrent
patreon.com/feross
feross.org/thanks
patreon.com/evanyou
Burnout in the tech industry (and why we need to talk about it)
Something missing or broken? PRs welcome!
Mad science, WebTorrent, WebRTC (Interview)
Feross Aboukhadijeh joined the show this week to talk with us about his backstory, passive income, WebTorrent, WebRTC, Electron and the ins and outs of packaging apps for all platforms.
Join the discussion
Changelog++ members support our work, get closer to the metal, and make the ads disappear. Join today!
Sponsors:
Rollbar – Put errors in their place! Full-stack error tracking for all apps in any language.
Toptal – Scale your team and hire the top 3% of developers and designers at Toptal. Email Adam at adam@changelog.com for a personal introduction to Toptal.
GoCD – GoCD is an on-premise open source continuous delivery server created by ThoughtWorks that lets you automate and streamline your build-test-release cycle for reliable, continuous delivery of your product.
Node.js Interactive – Node.js Interactive is a conference for the Node community focused on education and community building. Use the code CNGJS16 to get 15% off registration.
Featuring:
Feross Aboukhadijeh – Website, GitHub, X
Adam Stacoviak – Website, GitHub, LinkedIn, Mastodon, X
Jerod Santo – Website, GitHub, LinkedIn, Mastodon, X
Show Notes:
JavaScript Standard Style Guide
Study Notes is Feross’s passive income maker that enables him to work on open source and other stuff he’s interested in
FreeTheFlash - Hilarious media entertainment brought to you by FreeTheFlash Entertainment
Webmaster World
WebTorrent - A streaming torrent client for the web browser and the desktop
WebTorrent Desktop is the desktop Torrent client built with Electron
WebTorrent Desktop on GitHub
Instant.io
The Changelog #216 - Electron and Cross Platform Desktop Apps with Zeke Sikelianos
Mojibar - Emoji searcher but as a menubar app built with Electron
Something missing or broken? PRs welcome!