#feross
Folks that know Feross and the socket crew know this is well deserved
Today is a big day for @socket.dev. We raised a $60M Series C at a $1B valuation, led by Thrive Capital. 20,000+ orgs, 1.5M repos protected, 1,000+ supply chain attacks blocked per week. 3/5 FAANG companies are customers. We're just getting started.
May 20, 2026 at 5:24 PM
Open source maintainers were already overloaded. AI-driven vulnerability discovery is about to send a lot more findings their way.

@feross.bsky.social on TBPN 👇

socket.dev/blog/feross-...
Feross on TBPN: Socket's Series C and the State of Software ...
Feross Aboukhadijeh joins TBPN to discuss Socket's $60M Series C, 500%+ ARR growth, AI's impact on open source, and the rise in supply chain attacks.
socket.dev
May 27, 2026 at 9:22 PM
Cool tool of the day: wormhole.app

Ever wanted to send a big file (up to 10GB) file to someone easily? it expires in a day, but I have found it super useful for sending around zip files.

this free service is secure and built by Feross, a genuine wizard.

wormhole.app
Wormhole - Simple, private file sharing
Wormhole lets you share files with end-to-end encryption and a link that automatically expires.
wormhole.app
January 9, 2025 at 2:09 AM
Breaking kayfabe to say that Feross & crew are fucking killing it right now, and are doing a way better job than npmhubsoft at keeping people informed in our new "all supply chain attacks all the time" phase of existence.
socket.dev Socket @socket.dev · Sep 16
🚨 Update: The "Shai-Hulud" supply chain attack has expanded to nearly 500 trojanized npm packages, including several from CrowdStrike, all using the same malware first seen in Tinycolor.

Full details and package list: socket.dev/blog/ongoing... #NodeJS #JavaScript
Ongoing Supply Chain Attack Targets CrowdStrike npm Packages...
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Halud" supply chain attack that previously hit Tinycolor and dozen...
socket.dev
September 16, 2025 at 9:44 PM
If you want updates on the Axios supply chain attack I recommend monitoring these people's posts:

- @dez_
- @feross
- @ramimacisabird
- @_JohnHammond

These four seem to be on top of it. People are also commenting on their posts and sharing information.

I was initially sharing
March 31, 2026 at 5:34 AM
Hackers just hijacked npm packages with 2–3 billion weekly downloads.
All that access… and they only stole $500 of crypto 🤯

Sloppiest supply chain attack ever.
But if they’d been smarter? Could’ve been catastrophic.

I broke it down on @riskybusiness.bsky.social.

Full video here 👇
Feross Aboukhadijeh drops by RiskyBiz to talk about the big, dumb npm supply chain attack
YouTube video by Socket Security
www.youtube.com
September 10, 2025 at 5:48 PM
"The whole software supply chain is built on blind trust. You're downloading code from random people on the internet that you've never met, and you're like, let's just run it." - @feross.bsky.social on TBPN talking about the Axios compromise.

Full interview → socket.dev/blog/feross-...
April 8, 2026 at 11:17 PM
Feross and team are the real deal. They are aiming squarely at one of the most painful and dysfunctional parts of modern development, and continue doing great work to help developers deal with it.
We just bought a company.

Why? Because vulnerability scanning is fundamentally broken. And I’m tired of pretending it’s fine.

We acquired Coana, the best reachability analysis engine on the planet.
Socket Acquires Coana To Build Out Its SCA Capabilities
Better analysis of open-source software is vital to help developers close the door on cyber attacks and breaches, but this also creates the danger of "alert fatigue"
www.forbes.com
April 24, 2025 at 4:56 PM
🚀 @socket.dev's first appearance on TBPN. We talked about what's been an intense week in supply chain security and why AI is accelerating the problem.

We've been building for exactly this moment.

www.youtube.com/watch?v=EeJg...
On TBPN: Feross Discusses the Axios Attack and Today’s Open Source Security Landscape
YouTube video by Socket Security
www.youtube.com
April 8, 2026 at 9:24 PM
Made a LoRA of Ross from Fire Emblem Sacred Stones 🛡

LoRA: civitai.com/models/13561...

All characters depicted are 18 or older.

#Ross #fireemblem #fireemblemsacredstones #fess #fe #fesacredstones #feross #ai #aigay #aigayporn #aiyaoi #aibara #ainsfw #gay #gayporn #yaoi #bara #nsfw #man #lora
March 14, 2025 at 4:14 PM
🚨 The npm ecosystem just got hit with another major supply chain attack.

If your app uses npm packages (spoiler: it does), you must hear this.

We're sitting down with @feross from @SocketSecurity to dissect what happened and how to protect yourself.

Thread 👇
October 7, 2025 at 9:48 AM
Anyone gotten #simple-peer working for sending/receiving data? Or has time and network/NAT development left it broken?

#webrtc #browser #javascript

github.com/feross/simpl...
GitHub - feross/simple-peer: 📡 Simple WebRTC video, voice, and data channels
📡 Simple WebRTC video, voice, and data channels. Contribute to feross/simple-peer development by creating an account on GitHub.
github.com
April 6, 2025 at 7:51 AM
RE: https://infosec.exchange/@feross/116494691306371498

We seem to be seeing significant supply chain attacks every day now. How do we get out of this tech doom loop?
infosec.exchange
April 30, 2026 at 6:43 PM
Socket usually detects malware fast.
There's still an exposure window, but it is greatly reduced, and the free version should even improve in the future to report AI-detected probable malware

x.com/feross/statu...
May 22, 2026 at 10:18 AM
🎧 Socket CEO @feross.bsky.social joined Tim Winkler on The Pair Program podcast to talk about the open web, open source security, and how Socket is tackling supply chain attacks. Check out this fun episode. ↣

socket.dev/blog/feross-...
The Pair Program Podcast: Feross Aboukhadijeh on Preserving ...
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program ...
socket.dev
March 10, 2025 at 10:02 PM
Feross Aboukhadijeh is the founder and CEO of @socket.dev. He joins @joshuakgoldberg.com to talk about his career, open source supply chain attacks, practical security lessons, the expanding attack surface in software development, and more.

@feross.bsky.social

bit.ly/4iMDU14
Blocking Software Supply Chain Attacks with Feross Aboukhadijeh - Software Engineering Daily
Modern software relies heavily on open source dependencies, often pulling in thousands of packages maintained by developers all over the world. This accelerates innovation but also creates serious sup...
softwareengineeringdaily.com
December 9, 2025 at 10:36 AM
Recently went on @changelog.com to talk about the wild surge of npm supply chain attacks… and what developers can actually do to stay safe 🔥

We broke down the real, practical steps every team should take:

• Lockfiles matter more than people think
• Delay new package versions to dodge fresh malware
Feross on the most serious supply chain attacks in npm history (and what we can do about it)
YouTube video by Changelog
www.youtube.com
November 12, 2025 at 7:04 PM
Congrats Feross!
May 20, 2026 at 3:25 PM
Amazing and hard to imagine a founder who deserves it more!

Feross is a good human and building something ACTUALLY USEFUL to make our lives a little bit safer everyday.

Congrats to you and the Socket team!!
Today is a big day for @socket.dev. We raised a $60M Series C at a $1B valuation, led by Thrive Capital. 20,000+ orgs, 1.5M repos protected, 1,000+ supply chain attacks blocked per week. 3/5 FAANG companies are customers. We're just getting started.
May 20, 2026 at 8:05 PM
🚨 Another major npm supply-chain attack just hit — and it’s a wake-up call for anyone building on open source.

I join @nodeland.dev — creator of Fastify, Node.js core maintainer, and an open-source legend — and Luca Maraschi to break down how attackers are infiltrating npm.
Inside the Latest npm Attack (with Feross Aboukhadijeh)
YouTube video by Platformatic
youtube.com
October 8, 2025 at 6:07 PM
Hey congratulations Feross!! Well deserved
May 20, 2026 at 5:23 PM
#axios has been compromised

nitter.net/feross/statu...
nitter.net
March 31, 2026 at 8:03 AM
• Audit your GitHub Actions
• And yes… add a firewall for your dependencies

If you haven't heard about Socket Firewall. It’s free. It works with npm, PyPI, and Cargo. And it blocks malicious packages before they hit your machine. No config. No API keys. Just install and go ⚡️
Feross on the most serious supply chain attacks in npm history (and what we can do about it)
YouTube video by Changelog
www.youtube.com
November 12, 2025 at 7:04 PM