Opens profile photo
Follow
Socket
@SocketSecurity
Secure your JavaScript supply chain. Depend on Socket to protect your app from malicious dependencies lurking in your open source supply chain.
node_modules/socket.devJoined November 2021

Socket’s Tweets

Curious about npm supply chain attacks and what you can do to defend against them? Come see speak at to learn about the latest attacker techniques and get concrete tips to secure your code!
Quote Tweet
Do you know what's really going on in your node_modules folder? @feross will help to understand the scope of the supply chain threats against the open source ecosystem, with a focus on npm and JavaScript. #ejs Details👉bit.ly/3LS7ctp Tickets🎫enterjs.de/tickets.php
enterJS 22: Do you know what's really going on in your node_modules folder? @feross will help to understand the scope of the supply chain threats against the open source ecosystem, with a focus on npm and JavaScript.
GIF
3

Topics to follow

Sign up to get Tweets about the Topics you follow in your Home timeline.

Carousel

I had a super fun conversation with , , and the crew! 🗣 Why does seem to have more attacks than other ecosystems? 🗣 How are vulnerabilities and malware different? 🗣 How does work behind-the-scenes? �?�? Listen now!
Quote Tweet
🎧 New episode of JS Party! 🎧 💬 Making moves on supply chain security 💫 w/ @feross @bcomnes & @MikolaLysenko 🎙 hosted by @nicknisi & @b0neskull 🗃�? tagged #javascript #infosec #npm 💚 jsparty.fm/219
8
10
🗣�? : Open-source supply chain attacks 🗒�? Majority of our code is written by volunteers and we trust without reading. 🤔 Malicious code often in npm install scripts, sometimes a typo away from popular package names. ➡�? socket.dev #CascadiaJS
4
5
Show this thread
I had a SUPER FUN conversation with the team. We talked about JavaScript supply chain attacks and why this is such a problem in 2022.
Quote Tweet
We talked to @feross about Wormhole last June. Now he joins us to talk about @SocketSecurity, a new security company that protects your most critical apps from supply chain attacks. Apple: apple.co/37EG6XN Spotify: spoti.fi/3qqpoCi Google: bit.ly/36D0x7d
Image
1
3
6
If you're a JS/TS developer, check this out. Also, the webgl viz deconstructing node_modules is 🔥
Quote Tweet
🚀 Exciting news! I'm ready to share the project I've been working on for the past 7 months! Introducing ✨ Socket ✨ ⚡�? Search millions of open source packages 🔒 Detect suspicious package updates in real-time 🛡 Block software supply chain attacks socket.dev
Show this thread
2
6
Excited to be speaking at Nordic.js for the second time! This is gonna be awesome! The JavaScript security space is evolving quickly these days, so there will be lots of new and exciting stuff to talk about by October I’m sure!
Quote Tweet
Give it up for Feross Aboukhadijeh (@feross) who is the Founder and CEO of Socket (@SocketSecurity) �?�?�? His talk is called “What's Really Going on Inside Your Node_Modules Folder�?. Get your ticket at nordicjs.com/2022/ #nordicjs
Show this thread
Image
2
22
Wow, this is a fabulous tool.
Quote Tweet
🚀 Exciting news! I'm ready to share the project I've been working on for the past 7 months! Introducing ✨ Socket ✨ ⚡�? Search millions of open source packages 🔒 Detect suspicious package updates in real-time 🛡 Block software supply chain attacks socket.dev
Show this thread
1
2
4
During his time at SPC, epitomized the builder mindset we value so much in members. We're thrilled to see Socket go public and proud to back it!
Quote Tweet
🚀 Exciting news! I'm ready to share the project I've been working on for the past 7 months! Introducing ✨ Socket ✨ ⚡�? Search millions of open source packages 🔒 Detect suspicious package updates in real-time 🛡 Block software supply chain attacks socket.dev
Show this thread
2
3
13
This is really cool. Npm supply chain attacks have become a norm. Totally agree that reactive CVE scanning is missing the point
Quote Tweet
🚀 Exciting news! I'm ready to share the project I've been working on for the past 7 months! Introducing ✨ Socket ✨ ⚡�? Search millions of open source packages 🔒 Detect suspicious package updates in real-time 🛡 Block software supply chain attacks socket.dev
Show this thread
1
2
3