Feross Aboukhadijeh
Coffee with Developers with Feross Aboukhadijeh of Socket about the xz backdoor
#1about 5 minutes
How the xz backdoor exploited maintainer burnout
The xz attack highlights how maintainer burnout creates opportunities for malicious actors to gain trust and take over critical open source projects.
#2about 4 minutes
A historical parallel with the event-stream NPM hack
The 2017 event-stream hack demonstrates a similar pattern of social engineering and highlights how lucky discoveries often expose these backdoors.
#3about 9 minutes
The growing problem of dependency bloat and rot
Modern package managers encourage massive dependency trees, which often include outdated or unnecessary packages that increase the attack surface.
#4about 10 minutes
Detecting protestware and other malicious behaviors
Automated tooling is essential for detecting malicious code like protestware by analyzing package behavior for suspicious activities like file deletion or network access.
#5about 4 minutes
The critical trade-offs of auto-updating dependencies
While updating dependencies protects against known vulnerabilities, updating too quickly can expose you to new, undiscovered supply chain attacks before the community finds them.
#6about 10 minutes
Taking responsibility for your software supply chain
Developers must take responsibility for their dependencies by using lock files, leveraging analysis tools, and understanding that open source transparency aids discovery but doesn't guarantee immediate safety.
Related jobs
Jobs that call for the skills explored in this talk.
Technoly GmbH
Berlin, Germany
€50-60K
Intermediate
Network Security
Security Architecture
+2
Hubert Burda Media
München, Germany
€80-95K
Intermediate
Senior
JavaScript
Node.js
+1
Matching moments
01:06 MIN
Malware campaigns, cloud latency, and government IT theft
Fake or News: Self-Driving Cars on Subscription, Crypto Attacks Rising and Working While You Sleep - Théodore Lefèvre
05:01 MIN
Comparing the security models of browsers and native apps
Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof
09:38 MIN
Technical challenges of shipping a cross-platform browser
Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof
06:46 MIN
How AI-generated content is overwhelming open source maintainers
WeAreDevelopers LIVE – You Don’t Need JavaScript, Modern CSS and More
01:15 MIN
Crypto crime, EU regulation, and working while you sleep
Fake or News: Self-Driving Cars on Subscription, Crypto Attacks Rising and Working While You Sleep - Théodore Lefèvre
06:23 MIN
The trend of browsers depending on online services
Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof
05:55 MIN
The security risks of AI-generated code and slopsquatting
Slopquatting, API Keys, Fun with Fonts, Recruiters vs AI and more - The Best of LIVE 2025 - Part 2
02:49 MIN
Using AI to overcome challenges in systems programming
AI in the Open and in Browsers - Tarek Ziadé
Featured Partners
Related Videos
Security Blindspots and How to Learn About Them - Anna Oliveira
Anna Oliveira
Hack-Proof The Node.js runtime: The Mechanics and Defense of Path Traversal Attacks
Sonya Moisset
Oops! Stories of supply chain shenanigans
Zbyszek Tenerowicz
Vulnerable VS Code extensions are now at your front door
Raul Onitza-Klugman & Kirill Efimov
You click, you lose: a practical look at VSCode's security
Thomas Chauchefoin & Paul Gerste
What The Hack is Web App Sec?
Jackie
Security in modern Web Applications - OWASP to the rescue!
Jakub Andrzejewski
101 Typical Security Pitfalls
Alexander Pirker
Related Articles
View all articles.png?w=240&auto=compress,format)



From learning to earning
Jobs that call for the skills explored in this talk.

aXite Security Tools
Amsterdam, Netherlands
Node.js
Angular
JavaScript



Abnormal AI
Intermediate
API
Spark
Kafka
Python

Port Zero GmbH
Berlin, Germany
€24-54K
Intermediate
Azure
Docker
Burp Suite
Kubernetes
+3

Ninedots
Python
CircleCI
Amazon Web Services (AWS)

Spektrum
Remote
Intermediate
Azure
Scrum
Gitlab
Docker
+13

Spektrum
Remote
Intermediate
Azure
Scrum
Gitlab
Docker
+13

Snyk
Charing Cross, United Kingdom
Senior
Azure
Docker
TypeScript
Kubernetes
Google Cloud Platform
+1