⚡️ Founder + CEO @SocketSecurity (socket.dev) • 🌲 Visiting lecturer @Stanford (cs253.stanford.edu) • ❤️ Open source @WebTorrentApp + @StandardJS

Stanford, CA
Pinned Tweet
🚨 Active supply chain attack on npm: keyv and cacheable are compromised right now, and the payload is a worm. The maintainer account behind both package families was compromised. On August 4, ten packages were republished with a malicious preinstall hook that steals your credentials, then uses those credentials to publish itself into more packages. Malicious versions are live on npm as I write this. These are foundational packages. keyv, cacheable, flat-cache, and file-entry-cache sit deep in dependency trees as transitive deps of common tooling like ESLint. Tens of millions of weekly downloads. Most affected users never installed them directly. What the payload does: • preinstall hook (setup.mjs) downloads a standalone Bun runtime and runs the second stage under it, sidestepping the host Node version and any Node-level monitoring • Harvests cloud and CI credentials: AWS/GCP/Azure keys, HashiCorp Vault tokens, Kubernetes service account tokens, GitHub Actions OIDC, and npm tokens • Repackages other npm packages with the same hook and republishes them through npm OIDC trusted publishing. This is what makes it a worm. • Exfiltrates over DNS and by committing stolen secrets to attacker-created GitHub repos • Plants autostart hooks in .claude and .vscode that execute when a developer or an AI coding agent opens the cloned repo. No npm install required. The detail worth sitting with: keyv@6.0.0 shipped with a passing npm provenance attestation. The build pipeline faithfully attested a source that was already trojanized. Signature verification alone did not stop this. Socket’s AI scanner flagged the malicious setup.mjs hook. If you install anything in the keyv, @keyv, or cacheable scopes: • Pin to the last known-clean version and rebuild lockfiles by integrity hash. No caret or tilde ranges, no npm update. • Better: block the entire keyv, @keyv, and cacheable scope at your registry proxy until the account is confirmed clean. • Rotate and revoke every credential reachable from any host that ran install scripts. npm and GitHub tokens should be revoked, not just rotated. Developing story. Socket is updating the affected-package list as new versions appear. Full research report with IoCs: socket.dev/blog/popular-npm-… If you are dealing with this right now and want help, email sales@socket.dev and we will spin up emergency white-glove assistance.
21
33
243
1,548,859
Marketing my cat like a new Apple product
362
8,506
77,266
1,621,764
Feross retweeted
Open source’s next chapter might be a thousand slightly different versions of the same software. socket.dev/blog/oj-vite-rust
3
4
14
2,613
Feross retweeted
Maintainers spend countless hours keeping the open source projects we all rely on secure. Too often, that work is unpaid. Socket is proud to join @openjsf's new Security Stewardship Program to help fund the researchers and maintainers protecting Node.js. socket.dev/blog/openjs-nodej…
3
14
1,911
Feross retweeted
Absolutely crazy that these two GitHub Actions which were quarantined could be reactivated with the malware still armed. Many of the these workflows run on a cron without any true repository activity trigging them.
3
7
2,014
Feross retweeted
Compromised MemOS packages on npm and PyPI spread cross-platform malware that steals developer credentials and may use stolen tokens to compromise more packages, @SocketSecurity reported. #cybersecurity #CISO #infosec bit.ly/4hdOXRQ
2
3
6
2,514
Feross retweeted
🚨 Two GitHub Actions compromised in May’s Mini Shai-Hulud campaign are running malware again. The repositories were re-enabled with malicious release tags intact, putting thousands of downstream repositories at risk. socket.dev/blog/mini-shai-hu…
4
8
37
9,572
Feross retweeted
Absolutely crazy that these two GitHub Actions which were quarantined could be reactivated with the malware still armed. Many of the these workflows run on a cron without any true repository activity trigging them.
🚨 Two GitHub Actions compromised in May’s Mini Shai-Hulud campaign are running malware again. The repositories were re-enabled with malicious release tags intact, putting thousands of downstream repositories at risk. socket.dev/blog/mini-shai-hu…
5
15
7,224
Feross retweeted
Not a rhetorical question. I actually don't know. Does anyone know
what happens when all the vanity custom domain name package names in golang expire?
1
5
841
Feross retweeted
🚨 MemTensor’s npm and PyPI packages have been compromised. Four malicious releases, including the latest version on both registries, drop cross-platform Go binaries that steal npm, PyPI, GitHub, AWS, SSH and other developer secrets. socket.dev/blog/memtensor-co…
6
10
2,638
Feross retweeted
Lovable rewrote Vite’s dev server in Rust. OJ uses ~75% less memory, and Lovable now provisions sandboxes in 3 seconds instead of 14.5. Evan You thinks AI may make these tailored rewrites more common to where everyone "maintains their own slop fork.” socket.dev/blog/oj-vite-rust
5
14
2,752
Two npm token changes worth knowing: 1. Tokens that bypass 2FA are losing power (no more changing maintainers or org membership). 2. ~Jan 2027: staged publishing, where a human with 2FA must approve the ship. The details: risky.biz/RBNEWSSI140/
1
1
6
1,356
Feross retweeted
The wildest part of a recent npm attack: the C2. The malware phoned home over libp2p, the BitTorrent DHT, IPFS, Ethereum smart contracts, and Nostr relays. Every decentralization protocol, as command-and-control: risky.biz/RBNEWSSI140/
4
14
2,261
Feross retweeted
Mikola is a Principal Software Engineer at @SocketSecurity, where his work focuses on software supply chain security: detecting malicious packages and fixing vulnerable ones.
1
1
2
650
Feross retweeted
🥁 𝐒𝐩𝐞𝐚𝐤𝐞𝐫 𝐀𝐧𝐧𝐨𝐮𝐧𝐜𝐞𝐦𝐞𝐧𝐭🎙️ Thrilled to have @MikolaLysenko on the #NodeConfEU 2026 stage! He'll tell us the story of "𝐃𝐞𝐥𝐞𝐭𝐞 𝐚𝐥𝐥 𝐂𝐕𝐄𝐬." 🎟️Don't miss it out; secure your tickets nodeconf.eu/
1
6
7
1,524
Feross retweeted
It's been one year since the Shai-Hulud npm worm was unleashed on the software supply chain, kicking off the worst year for npm security on record. It's now open source and has since torn through thousands of packages and organizations on its rampage. socket.dev/blog/happy-birthd…
7
15
2,778
npm 12's hidden trap: it silently skips install scripts, including the legit ones that compile native modules. Cue production failures, then teams blanket-allowing everything to make CI green. Flip the soft-fail into a hard-fail instead: risky.biz/RBNEWSSI140/
1
6
1,379
Feross retweeted
Supply chain attacks like these is another reason future OSS maintainers might shy away from commits from drive-by contributors, and keep contributors as a small clique within a smaller circle.
The scariest supply chain attack I've seen lately: Attacker gets one commit in. The project's own pipeline builds and publishes it via GitHub Actions, fully signed and attested. Cryptographically signed. Still malware. risky.biz/RBNEWSSI140/
1
7
1,631
Feross retweeted
We’re tracking more North Korea-linked PolinRider activity across GitHub and Packagist. New findings: 4 malicious dev versions, rewritten Git history, and obfuscated JavaScript planted in index.php and executed through PHP’s shell_exec() function. socket.dev/blog/polinrider-g…
8
19
3,279
Signatures and provenance are useful. But they never answer the real question: What does this code actually do when you run it? What does it touch? What does it connect to? That's the source of truth: risky.biz/RBNEWSSI140/
2
1,313