feross
Tues Sep 1, 2009 4:56am PST
Karma:
47627
about
Founder & CEO, Socket <https://socket.dev> – Socket makes a developer-first security platform that prevents vulnerable and malicious open source dependencies from infiltrating your software supply chain.

Stanford visiting lecturer, CS 253 Web Security <https://cs253.stanford.edu> – Principles of web security, attacks and countermeasures, and more...

Open source maintainer – 100+ open source packages on npm, including WebTorrent <https://webtorrent.io>, StandardJS <https://standardjs.com>, BitMidi <https://bitmidi.com>, simple-peer <https://github.com/feross/simple-peer>, and more <https://socket.dev/npm/user/feross>.

You can reach me at {my username}@feross.org, or find out more on my website: https://feross.org/resume

[ my public key: https://keybase.io/feross; my proof: https://keybase.io/feross/sigs/gO6pVIJ1DXdy9Y21yil6nlyk_by5BE_GaaWOOQJ5PvQ ]

submitted
Fri Oct 10, 2025 10:32pm PST
Socket Integrates with Bun 1.3's Security Scanner API
@feross
2
Fri Oct 10, 2025 10:01pm PST
North Korea's Contagious Interview Campaign Escalates: 338 Malicious NPM
@feross
2
Fri Oct 10, 2025 5:01pm PST
It's OpenAI's world, we're just living in it
@feross
21
249
122
Fri Oct 10, 2025 4:47pm PST
Next.js 16 (Beta)
@feross
2
Fri Oct 10, 2025 4:15pm PST
Fascism can't mean both a specific ideology and a legitimate target
@feross
20
87
32
Fri Oct 10, 2025 4:00pm PST
Google's OSV Fix Just Added 500 New Advisories – All Thanks to One Small Policy
@feross
1
Thurs Oct 9, 2025 6:32pm PST
First Brands Is Missing Some Money
@feross
1
1
1
Thurs Oct 9, 2025 5:47pm PST
Malicious NPM Packages Host Phishing Infrastructure Targeting 135
@feross
2
Thurs Oct 9, 2025 5:31pm PST
Python 3.14 Released with Template String Literals, Deferred Annotations, and
@feross
2
Thurs Oct 9, 2025 5:03pm PST
September 2025 (Version 1.105)
@feross
1
Thurs Oct 9, 2025 3:16pm PST
Socket Integrates with Bun 1.3's Security Scanner API
@feross
1
1
1
Thurs Oct 9, 2025 10:02am PST
The OpenAI Hype Cycle, Microsoft's Game Pass Failure, Verizon's Satellites
@feross
1
Thurs Oct 9, 2025 9:47am PST
Tracy Britt Cool: Brick by Brick
@feross
1
Tues Oct 7, 2025 10:17pm PST
Python 3.14 Released with Template String Literals, Deferred Annotations, and
@feross
6
Tues Oct 7, 2025 6:02pm PST
Sports Bets at the Stock Exchange
@feross
1
1
3
Tues Oct 7, 2025 4:03pm PST
Bring Python ASGI to Your Node.js Applications
@feross
1
Tues Oct 7, 2025 3:05pm PST
Is everyone switching to MoQ from WebRTC?
@feross
1
3
12
Mon Oct 6, 2025 5:32pm PST
OpenAI is good at deals
@feross
13
40
97
Mon Oct 6, 2025 4:17pm PST
Sora, AI Bicycles, and Meta Disruption
@feross
14
51
76
Mon Oct 6, 2025 4:01pm PST
Renewing Our Open Source Pledge for 2025
@feross
2
Fri Oct 3, 2025 9:32pm PST
Online Identity Verification with the Digital Credentials API
@feross
2
2
20
Fri Oct 3, 2025 3:17am PST
Stablecoins Make Banking Narrower
@feross
1
Fri Oct 3, 2025 3:02am PST
Release Notes for Safari Technology Preview 229
@feross
3
Fri Oct 3, 2025 2:16am PST
Vote in the 2025 Non-Book Review Contest
@feross
1
Fri Oct 3, 2025 2:03am PST
Core Web Vitals
@feross
2
Thurs Oct 2, 2025 11:47pm PST
PodRocket Podcast: Inside the Recent NPM Supply Chain Attacks
@feross
6
Wed Oct 1, 2025 4:04am PST
Package Maintainers Call for Improvements to GitHub's New NPM Security Plan
@feross
1
1
3
Tues Sep 30, 2025 5:46pm PST
Hedge funds have to be big
@feross
12
47
36
Tues Sep 30, 2025 2:17pm PST
Socket Firewall: Free, Proactive Protection for Your Software Supply
@feross
8
Fri Sep 26, 2025 10:02pm PST
Review: The Russo-Ukrainian War
@feross
15
Fri Sep 26, 2025 2:32pm PST
2025.39: The YouTube Juggernaut
@feross
2
Tues Sep 23, 2025 3:03pm PST
The Intelligent Command Center for Node.js Is Now Open Source
@feross
1
Tues Sep 23, 2025 11:47am PST
OpenAI does WebRTC in the new GPT-realtime
@feross
4
Tues Sep 23, 2025 10:02am PST
The YouTube Tip of the Google Spear
@feross
5
Mon Sep 22, 2025 6:16pm PST
Bitcoin Treasury Company M&A
@feross
1
1
1
Fri Sep 19, 2025 8:16pm PST
Review: Project Xanadu – The Internet That Might Have Been
@feross
1
1
10
Fri Sep 19, 2025 2:17pm PST
2025.38: Meta, YouTube, and Tech Press Attention
@feross
1
Thurs Sep 18, 2025 2:33pm PST
Meta Ray-Ban Display, Why Less Is More, Price and the Neural Band
@feross
2
Thurs Sep 18, 2025 2:17pm PST
Ed Stack: Lessons from Dick's Sporting Goods
@feross
1
Wed Sep 17, 2025 7:31pm PST
Identifying and Preventing Fraudulent Engineering Candidates: An Investigation
@feross
3
Mon Sep 15, 2025 11:29pm PST
Active NPM supply chain attack: Tinycolor and 40 Packages Compromised
@feross
6
36
85
Thurs Sep 11, 2025 7:16pm PST
An Interview with Dan Kim About Intel, Nvidia, and the U.S. Government
@feross
1
Thurs Sep 11, 2025 6:46pm PST
Lulu Cheng Meservey: How to Build a Cult
@feross
1
1
5
Thurs Sep 11, 2025 6:31pm PST
Book Review: If Anyone Builds It, Everyone Dies
@feross
16
Thurs Sep 11, 2025 6:00pm PST
Rust Support Now in Beta
@feross
4
Wed Sep 10, 2025 5:31pm PST
Feross on Risky Business Weekly Podcast: NPM's Ongoing Supply Chain Attacks
@feross
1
Wed Sep 10, 2025 12:01pm PST
Kerberoasting
@feross
15
69
206
Wed Sep 10, 2025 10:47am PST
iPhones 17 and the Sugar Water Trap
@feross
1
4
9
Tues Sep 9, 2025 8:01pm PST
Tier 1 Reachability: Precision CVE Triage for Enterprise Teams
@feross
3
Tues Sep 9, 2025 4:15pm PST
DuckDB NPM Account Compromised in Continuing Supply Chain Attack
@feross
1
1
27
Fri Sep 5, 2025 9:16pm PST
Malicious NPM Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet
@feross
2
Fri Sep 5, 2025 3:32pm PST
Rv Is a New Rust-Powered Ruby Version Manager Inspired by Python's Uv
@feross
1
1
3
Fri Sep 5, 2025 12:16pm PST
Review: Participation in Phase I Clinical Pharmaceutical Research
@feross
2
Thurs Sep 4, 2025 3:46pm PST
Stop Burning Money on Performance Firefighting
@feross
2
Thurs Sep 4, 2025 10:01am PST
An Interview with Cloudflare Founder and CEO Matthew Prince About Internet
@feross
1
3
Thurs Sep 4, 2025 7:01am PST
Links for September 2025
@feross
1
Wed Sep 3, 2025 10:33pm PST
Release Notes for Safari Technology Preview 227
@feross
1
1
2
Wed Sep 3, 2025 8:17pm PST
Nx Investigation Reveals GitHub Actions Workflow Exploit Led to NPM Token Theft
@feross
4
Wed Sep 3, 2025 6:47pm PST
Sports Team Owners Like to Win
@feross
1
1
2
Wed Sep 3, 2025 4:18pm PST
Watt 3
@feross
1
Tues Sep 2, 2025 5:01pm PST
Next-Generation Flamegraph Visualization for Node.js
@feross
17
Tues Sep 2, 2025 3:02pm PST
Made by Google 2025, AI Trade-Offs, Google and the Long-Term
@feross
1
Mon Sep 1, 2025 9:03pm PST
Massimo
@feross
1
Fri Aug 29, 2025 8:02pm PST
Wallet-Draining NPM Package Impersonates Nodemailer to Hijack Crypto
@feross
3
Thurs Aug 28, 2025 5:46pm PST
Benedict Evans: Why AI Isn't What You Think
@feross
1
1
2
Thurs Aug 28, 2025 5:32pm PST
The Economics of Envy
@feross
5
Wed Aug 27, 2025 6:19pm PST
VS Code Dev Days – Join an event near you to learn about AI-assisted development
@feross
2
Wed Aug 27, 2025 6:02pm PST
Nx NPM Packages Compromised in Supply Chain Attack Weaponizing AI CLI Tools
@feross
1
1
3
Tues Aug 26, 2025 6:16pm PST
Biotech Dividend Arrived Early
@feross
1
1
1
Thurs Aug 21, 2025 5:32pm PST
Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials Via
@feross
3
Thurs Aug 21, 2025 5:02pm PST
John Bragg: The Unknown Billionaire Who Controls Half The
@feross
2
2
5
Thurs Aug 21, 2025 1:03am PST
Release Notes for Safari Technology Preview 226
@feross
1
2
2
Wed Aug 20, 2025 11:02pm PST
Rspack Introduces Rslint, a TypeScript-First Linter Written in Go
@feross
4
Mon Aug 18, 2025 10:16pm PST
Oxlint Introduces Type-Aware Linting Preview
@feross
4
Sat Aug 16, 2025 2:16am PST
New Website "Is It FOSS?" Tracks Transparency in Open Source Distribution
@feross
1
1
8
Fri Aug 15, 2025 1:01pm PST
Review: Dating Men in the Bay Area
@feross
5
8
22
Fri Aug 15, 2025 10:17am PST
2025.33: Meta and the Benefit of the Doubt
@feross
1
Thurs Aug 14, 2025 3:02pm PST
In Defense of the Amyloid Hypothesis
@feross
2
2
13
Thurs Aug 14, 2025 2:46pm PST
Facebook Is Dead; Long Live Meta
@feross
2
Thurs Aug 14, 2025 4:02am PST
Astral Launches Pyx: A Python-Native Package Registry
@feross
1
1
3
Wed Aug 13, 2025 6:02pm PST
Static vs. Runtime Reachability: Insights from Latio's on the Record Podcast
@feross
2
Wed Aug 13, 2025 3:15am PST
Dictator Book Club: Mussolini on Fascism
@feross
4
Tues Aug 12, 2025 10:18pm PST
A gentle introduction to anchor positioning
@feross
12
46
131
Tues Aug 12, 2025 8:47pm PST
Opengrep Adds Apex Support and New Rule Controls in Latest Updates
@feross
5
Tues Aug 12, 2025 4:00pm PST
Dicing an onion, the mathematically optimal way
@feross
4
Tues Aug 12, 2025 11:17am PST
Highlights from the Comments on Liberalism and Communities
@feross
1
Tues Aug 12, 2025 10:02am PST
China AI Chips, a China Chip Control Framework, Whither HBM
@feross
1
Wed Aug 6, 2025 4:06pm PST
TC39 Advances 11 Proposals for Math Precision, Binary APIs, and More
@feross
3