Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Feross on Risky Business Weekly Podcast: npm’s Ongoing Suppl...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
300
Company Posts That Month
18
Language
English
Hacker News Points
-
Post removed?
No
Summary

Feross Aboukhadijeh, CEO of Socket, discussed the recent npm supply chain attacks on the Risky Business Weekly podcast, highlighting their limited impact despite targeting prolific JavaScript package maintainers like qix and DuckDB. He explained that, in terms of download counts, this was one of the largest compromises in the npm ecosystem, affecting packages with 2-3 billion downloads per week. However, the attackers only managed to collect a modest $500 in Ethereum and roughly $50 in other cryptocurrencies, which Aboukhadijeh described as disappointing given their level of access. He warned that the situation could have been significantly worse if the attackers had been more strategic, underscoring the potential threat to open source software supply chains if future attacks are executed with greater sophistication.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.