Feross (@feross) 's Twitter Profile
Feross

@feross

⚡️ Founder + CEO @SocketSecurity (socket.dev) • 🌲 Visiting lecturer @Stanford (cs253.stanford.edu) • ❤️ Open source @WebTorrentApp + @StandardJS

ID: 15692193

linkhttps://feross.org calendar_today01-08-2008 18:03:27

27,27K Tweet

28,28K Takipçi

1,1K Takip Edilen

Socket (@socketsecurity) 's Twitter Profile Photo

🚀 Introducing Socket MCP: real-time dependency scoring for AI-generated code. Stop risky packages at the prompt: 🔹 Fits naturally into AI-assisted workflows 🔹 Powered by Socket’s trusted depscore API 🔹 Checks supply chain risk, vulns, maintenance socket.dev/blog/socket-mcp

Sarah Gooding (@pollyplummer) 's Twitter Profile Photo

Developers are importing dependencies suggested by LLMs, often without knowing if those packages have supply chain risks, are vulnerable, unmaintained, or even real. Today, we're introducing Socket MCP: real-time dependency scoring inside the AI workflow.

Socket (@socketsecurity) 's Twitter Profile Photo

🚨 PyPI malware alert: A single malicious #Python package is silently hijacking #Solana wallets by monkey-patching key generation. 5 decoy packages, 25K+ downloads, and the stolen keys are exfiltrated on-chain. Full research → socket.dev/blog/monkey-pa… #crypto #CyberSecurity

William Mason (feat Bear) (@wbmason) 's Twitter Profile Photo

I’ve kinda wondered - with how fast AI is moving and being experimented with rapidly especially in the open source arena, just how many things like this are happening under the surface with nobody currently the wiser.

Feross (@feross) 's Twitter Profile Photo

1/ We just caught four malicious npm packages trying to drain your crypto wallet. Obfuscated code. Russian email. Hardcoded wallet. Designed to steal up to 85% of your ETH or BNB — silently. 👇 Here’s how they did it & why it matters 🧵

Sarah Gooding (@pollyplummer) 's Twitter Profile Photo

It’s wild how fast opportunistic threat actors create these attacks. Just days after Vietnam banned Telegram, someone published malicious #Ruby gems to steal Telegram Messenger bot tokens from CI pipelines. cc: Short Ruby Newsletter Lucian Ghinda Pavel Durov

Feross (@feross) 's Twitter Profile Photo

Really excited that Socket is one of the first to support the awesome new Python lock file standard. pylock.toml is a really big step towards finally solving python package management woes!