feross
Tues Sep 1, 2009 4:56am PST
Karma:
47453
about
Founder & CEO, Socket <https://socket.dev> – Socket makes a developer-first security platform that prevents vulnerable and malicious open source dependencies from infiltrating your software supply chain.

Stanford visiting lecturer, CS 253 Web Security <https://cs253.stanford.edu> – Principles of web security, attacks and countermeasures, and more...

Open source maintainer – 100+ open source packages on npm, including WebTorrent <https://webtorrent.io>, StandardJS <https://standardjs.com>, BitMidi <https://bitmidi.com>, simple-peer <https://github.com/feross/simple-peer>, and more <https://socket.dev/npm/user/feross>.

You can reach me at {my username}@feross.org, or find out more on my website: https://feross.org/resume

[ my public key: https://keybase.io/feross; my proof: https://keybase.io/feross/sigs/gO6pVIJ1DXdy9Y21yil6nlyk_by5BE_GaaWOOQJ5PvQ ]

submitted
Thurs Sep 18, 2025 2:33pm PST
Meta Ray-Ban Display, Why Less Is More, Price and the Neural Band
@feross
2
Thurs Sep 18, 2025 2:17pm PST
Ed Stack: Lessons from Dick's Sporting Goods
@feross
1
Wed Sep 17, 2025 7:31pm PST
Identifying and Preventing Fraudulent Engineering Candidates: An Investigation
@feross
3
Mon Sep 15, 2025 11:29pm PST
Active NPM supply chain attack: Tinycolor and 40 Packages Compromised
@feross
6
36
82
Thurs Sep 11, 2025 7:16pm PST
An Interview with Dan Kim About Intel, Nvidia, and the U.S. Government
@feross
1
Thurs Sep 11, 2025 6:46pm PST
Lulu Cheng Meservey: How to Build a Cult
@feross
1
1
5
Thurs Sep 11, 2025 6:31pm PST
Book Review: If Anyone Builds It, Everyone Dies
@feross
16
Thurs Sep 11, 2025 6:00pm PST
Rust Support Now in Beta
@feross
4
Wed Sep 10, 2025 5:31pm PST
Feross on Risky Business Weekly Podcast: NPM's Ongoing Supply Chain Attacks
@feross
1
Wed Sep 10, 2025 12:01pm PST
Kerberoasting
@feross
15
69
206
Wed Sep 10, 2025 10:47am PST
iPhones 17 and the Sugar Water Trap
@feross
1
4
9
Tues Sep 9, 2025 8:01pm PST
Tier 1 Reachability: Precision CVE Triage for Enterprise Teams
@feross
3
Tues Sep 9, 2025 4:15pm PST
DuckDB NPM Account Compromised in Continuing Supply Chain Attack
@feross
1
1
27
Fri Sep 5, 2025 9:16pm PST
Malicious NPM Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet
@feross
2
Fri Sep 5, 2025 3:32pm PST
Rv Is a New Rust-Powered Ruby Version Manager Inspired by Python's Uv
@feross
1
1
2
Fri Sep 5, 2025 12:16pm PST
Review: Participation in Phase I Clinical Pharmaceutical Research
@feross
2
Thurs Sep 4, 2025 3:46pm PST
Stop Burning Money on Performance Firefighting
@feross
2
Thurs Sep 4, 2025 10:01am PST
An Interview with Cloudflare Founder and CEO Matthew Prince About Internet
@feross
1
3
Thurs Sep 4, 2025 7:01am PST
Links for September 2025
@feross
1
Wed Sep 3, 2025 10:33pm PST
Release Notes for Safari Technology Preview 227
@feross
1
1
2
Wed Sep 3, 2025 8:17pm PST
Nx Investigation Reveals GitHub Actions Workflow Exploit Led to NPM Token Theft
@feross
4
Wed Sep 3, 2025 6:47pm PST
Sports Team Owners Like to Win
@feross
1
1
2
Wed Sep 3, 2025 4:18pm PST
Watt 3
@feross
1
Tues Sep 2, 2025 5:01pm PST
Next-Generation Flamegraph Visualization for Node.js
@feross
17
Tues Sep 2, 2025 3:02pm PST
Made by Google 2025, AI Trade-Offs, Google and the Long-Term
@feross
1
Mon Sep 1, 2025 9:03pm PST
Massimo
@feross
1
Fri Aug 29, 2025 8:02pm PST
Wallet-Draining NPM Package Impersonates Nodemailer to Hijack Crypto
@feross
3
Thurs Aug 28, 2025 5:46pm PST
Benedict Evans: Why AI Isn't What You Think
@feross
1
1
2
Thurs Aug 28, 2025 5:32pm PST
The Economics of Envy
@feross
5
Wed Aug 27, 2025 6:19pm PST
VS Code Dev Days – Join an event near you to learn about AI-assisted development
@feross
2
Wed Aug 27, 2025 6:02pm PST
Nx NPM Packages Compromised in Supply Chain Attack Weaponizing AI CLI Tools
@feross
1
1
3
Tues Aug 26, 2025 6:16pm PST
Biotech Dividend Arrived Early
@feross
1
1
1
Thurs Aug 21, 2025 5:32pm PST
Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials Via
@feross
3
Thurs Aug 21, 2025 5:02pm PST
John Bragg: The Unknown Billionaire Who Controls Half The
@feross
2
2
5
Thurs Aug 21, 2025 1:03am PST
Release Notes for Safari Technology Preview 226
@feross
1
2
2
Wed Aug 20, 2025 11:02pm PST
Rspack Introduces Rslint, a TypeScript-First Linter Written in Go
@feross
4
Mon Aug 18, 2025 10:16pm PST
Oxlint Introduces Type-Aware Linting Preview
@feross
4
Sat Aug 16, 2025 2:16am PST
New Website "Is It FOSS?" Tracks Transparency in Open Source Distribution
@feross
1
1
8
Fri Aug 15, 2025 1:01pm PST
Review: Dating Men in the Bay Area
@feross
5
8
22
Fri Aug 15, 2025 10:17am PST
2025.33: Meta and the Benefit of the Doubt
@feross
1
Thurs Aug 14, 2025 3:02pm PST
In Defense of the Amyloid Hypothesis
@feross
2
2
13
Thurs Aug 14, 2025 2:46pm PST
Facebook Is Dead; Long Live Meta
@feross
2
Thurs Aug 14, 2025 4:02am PST
Astral Launches Pyx: A Python-Native Package Registry
@feross
1
1
3
Wed Aug 13, 2025 6:02pm PST
Static vs. Runtime Reachability: Insights from Latio's on the Record Podcast
@feross
2
Wed Aug 13, 2025 3:15am PST
Dictator Book Club: Mussolini on Fascism
@feross
4
Tues Aug 12, 2025 10:18pm PST
A gentle introduction to anchor positioning
@feross
12
46
131
Tues Aug 12, 2025 8:47pm PST
Opengrep Adds Apex Support and New Rule Controls in Latest Updates
@feross
5
Tues Aug 12, 2025 4:00pm PST
Dicing an onion, the mathematically optimal way
@feross
4
Tues Aug 12, 2025 11:17am PST
Highlights from the Comments on Liberalism and Communities
@feross
1
Tues Aug 12, 2025 10:02am PST
China AI Chips, a China Chip Control Framework, Whither HBM
@feross
1
Wed Aug 6, 2025 4:06pm PST
TC39 Advances 11 Proposals for Math Precision, Binary APIs, and More
@feross
3
Thurs Jul 31, 2025 10:32pm PST
Suddenly, Trait-Based Embryo Selection
@feross
1
1
4
Thurs Jul 31, 2025 6:02pm PST
You Can Insider Trade NFTs Now
@feross
1
1
4
Thurs Jul 31, 2025 5:17pm PST
Rust Support in Socket
@feross
8
Thurs Jul 31, 2025 12:02am PST
My Heart of Hearts
@feross
3
Wed Jul 30, 2025 11:47pm PST
Ryan Petersen: Building the Hidden Engine of Global Trade
@feross
1
Wed Jul 30, 2025 8:01pm PST
Precomputed Reachability Analysis in Socket
@feross
2
Wed Jul 30, 2025 11:46am PST
Figma S-1, the Figma OS, Figma's AI Potential
@feross
5
Wed Jul 30, 2025 8:47am PST
Happy 20th Birthday MDN
@feross
3
Wed Jul 30, 2025 2:45am PST
Socket Now Protects the Chrome Extension Ecosystem
@feross
2
Tues Jul 29, 2025 8:32pm PST
Socket MCP for Claude Desktop
@feross
2
Tues Jul 29, 2025 12:32pm PST
Tesla and Samsung, Customer Service and Intel, the U.S. Semi Supply Chain
@feross
1
Thurs Jul 24, 2025 12:47am PST
Katharine Graham: The Washington Post
@feross
4
49
98
Wed Jul 23, 2025 9:17pm PST
Release Notes for Safari Technology Preview 224
@feross
2
Wed Jul 23, 2025 9:01pm PST
Toptal's GitHub Organization Hijacked: 10 Malicious Packages Published
@feross
3
Wed Jul 23, 2025 6:31pm PST
Meme Stocks Are Back
@feross
3
2
6
Wed Jul 23, 2025 3:47pm PST
Surveillance Malware Hidden in NPM and PyPI Packages Targets Developers With
@feross
1
1
4
Tues Jul 22, 2025 9:01pm PST
NPM 'Is' Package Hijacked in Expanding Supply Chain Attack
@feross
14
Tues Jul 22, 2025 4:02pm PST
June 2025 Baseline monthly digest
@feross
2
Tues Jul 22, 2025 3:47pm PST
Netflix Earnings, Apple and F1
@feross
2
Tues Jul 22, 2025 3:32pm PST
Daniel Kahneman: Algorithms Make Better Decisions Than You [the Knowledge
@feross
3
Tues Jul 22, 2025 2:46am PST
Bun 1.2.19 Adds Isolated Installs for Better Monorepo Support
@feross
5
Tues Jul 22, 2025 2:40am PST
Apparent Security Incident at Toptal
@feross
2
Mon Jul 21, 2025 6:16pm PST
Private Research Is the New Public Research
@feross
1
1
2
Mon Jul 21, 2025 6:01pm PST
Press Any Key for Bay Area House Party
@feross
1
1
8
Sat Jul 19, 2025 5:30pm PST
Prettier NPM Packages Compromised in Supply Chain Attack
@feross
4
7
45
Sat Jul 19, 2025 1:01am PST
Active Supply Chain Attack: NPM Phishing Campaign Leads to Prettier Tooling
@feross
2
Fri Jul 18, 2025 8:16pm PST
NPM Phishing Email Targets Developers with Typosquatted Domain
@feross
3
Fri Jul 18, 2025 6:04pm PST
Knip Hits 500 Releases with v5.62.0, Improving TypeScript Config Detection and
@feross
4
Fri Jul 18, 2025 4:46pm PST
2025.29: What It Takes to Change the Web
@feross
6
Fri Jul 18, 2025 4:02pm PST
Poor Passwords Tattle on AI Hiring Bot Maker Paradox.ai
@feross
1
1
3
Fri Jul 18, 2025 3:47pm PST
Review: Islamic Geometric Patterns in the Metropolitan Museum of Art
@feross
8
Thurs Jul 17, 2025 10:01pm PST
Open Source Maintainers Feeling the Weight of the EU's Cyber Resilience Act
@feross
3
Thurs Jul 17, 2025 7:34pm PST
Command GitHub's Coding Agent from VS Code
@feross
2
Thurs Jul 17, 2025 4:31pm PST
Daniel Kahneman: Algorithms Make Better Decisions Than You [the Knowledge
@feross
2
Wed Jul 16, 2025 10:01pm PST
Crates.io Implements Trusted Publishing Support
@feross
3
Wed Jul 16, 2025 1:32pm PST
Cloudflare's Content Independence Day, Google's Advantage, Monetizing AI
@feross
2
Wed Jul 16, 2025 1:31am PST
Tracking Protestware Spread: 28 NPM Packages Affected by Payload Targeting
@feross
2
Tues Jul 15, 2025 1:01pm PST
Book Review: Arguments About Aborigines
@feross
1
Tues Jul 15, 2025 10:02am PST
Cognition Buys Windsurf, Nvidia Can Sell to China, Grok 4 and Kimi
@feross
2