Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Risky Business Podcast: Why Open Source Software Needs Bette...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
396
Company Posts That Month
33
Language
English
Hacker News Points
-
Post removed?
No
Summary

In a segment of the Risky Business podcast, Socket founder Feross Aboukhadijeh and cybersecurity journalist Patrick Gray delve into the persistent threat of malicious packages within open source software registries like npm, RubyGems, PyPI, and Maven Central. Feross describes the alarming rate of over 100 new supply chain threats identified weekly, exploiting trust through tactics such as package hijacking and typosquatting, which can lead to serious risks like data exfiltration and unauthorized command execution. The discussion highlights the lack of a standardized system for tracking these threats, unlike the National Vulnerability Database for CVEs, with current practices often relying on private vendors like Socket. Feross suggests expanding the existing CVE infrastructure to include malicious package tracking, which could enhance detection and compliance. Additionally, the podcast examines the evolving sophistication of attacks, including the use of Ethereum smart contracts for operations, while noting that many succeed due to insufficient developer scrutiny, exemplified by incidents such as the event-stream and xz-utils attacks.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.