Feross Aboukhadijeh
Coffee with Developers with Feross Aboukhadijeh of Socket about the xz backdoor
#1about 5 minutes
How the xz backdoor exploited maintainer burnout
The xz attack highlights how maintainer burnout creates opportunities for malicious actors to gain trust and take over critical open source projects.
#2about 4 minutes
A historical parallel with the event-stream NPM hack
The 2017 event-stream hack demonstrates a similar pattern of social engineering and highlights how lucky discoveries often expose these backdoors.
#3about 9 minutes
The growing problem of dependency bloat and rot
Modern package managers encourage massive dependency trees, which often include outdated or unnecessary packages that increase the attack surface.
#4about 10 minutes
Detecting protestware and other malicious behaviors
Automated tooling is essential for detecting malicious code like protestware by analyzing package behavior for suspicious activities like file deletion or network access.
#5about 4 minutes
The critical trade-offs of auto-updating dependencies
While updating dependencies protects against known vulnerabilities, updating too quickly can expose you to new, undiscovered supply chain attacks before the community finds them.
#6about 10 minutes
Taking responsibility for your software supply chain
Developers must take responsibility for their dependencies by using lock files, leveraging analysis tools, and understanding that open source transparency aids discovery but doesn't guarantee immediate safety.
Related jobs
Jobs that call for the skills explored in this talk.
Matching moments
04:23 MIN
How malicious actors infiltrate open source projects
Reviewing 3rd party library security easily using OpenSSF Scorecard
08:22 MIN
How attackers exploit developers and packages
Vue3 practical development
08:16 MIN
Common attacks targeting software developers
Vulnerable VS Code extensions are now at your front door
27:19 MIN
Key takeaways on IDE and developer tool security
You click, you lose: a practical look at VSCode's security
05:13 MIN
How developers can become malware distribution vehicles
Stranger Danger: Your Java Attack Surface Just Got Bigger
00:02 MIN
Developers as an unintentional malware distribution vehicle
Walking into the era of Supply Chain Risks
18:24 MIN
The crisis of open source developer sustainability
The Future of Open Source
14:52 MIN
Human factors in open source supply chain risk
Stranger Danger: Your Java Attack Surface Just Got Bigger
Featured Partners
Related Videos
Security Blindspots and How to Learn About Them - Anna Oliveira
Anna Oliveira
Hack-Proof The Node.js runtime: The Mechanics and Defense of Path Traversal Attacks
Sonya Moisset
Oops! Stories of supply chain shenanigans
Zbyszek Tenerowicz
Vulnerable VS Code extensions are now at your front door
Raul Onitza-Klugman & Kirill Efimov
You click, you lose: a practical look at VSCode's security
Thomas Chauchefoin & Paul Gerste
What The Hack is Web App Sec?
Jackie
Security in modern Web Applications - OWASP to the rescue!
Jakub Andrzejewski
101 Typical Security Pitfalls
Alexander Pirker
Related Articles
View all articles.png?w=240&auto=compress,format)



From learning to earning
Jobs that call for the skills explored in this talk.



Security Engineer/Pentester
Port Zero GmbH
Berlin, Germany
€24-54K
Intermediate
Azure
Docker
Burp Suite
Kubernetes
+3

Frontend Engineer - Java & Open Source (Private & FS)
Version 1 Solutions Limited
Charing Cross, United Kingdom
Remote
Java
React
Python
Vue.js
+11

Student Assistant Backend Development of Security/Hacking Tools - C/C++
Fraunhofer-Gesellschaft
Darmstadt, Germany
C++
Agile Methodologies

H/F Développeur Backend Node.js / NestJS - Architecture Hexagonale & DDD
Sept Lieues
Paris, France
€65-70K
Go
C++
Java
Vue.js
+9

{"@context":"https://schema.org/","@type":"JobPosting","title":"Software Engineer 2 - Full-Stack - Behavioral Security Products
Abnormal AI
Intermediate
API
Spark
Kafka
Python

Senior Offensive Security Engineer
Openchip & Software Technologies
Barcelona, Spain
Senior
DNS
GIT
JIRA
Linux
SharePoint
+1

{"@context":"https://schema.org","@graph":[{"@context":"https://schema.org/","@type":"JobPosting","@id":"#jobPosting","title":"Application Security Engineer
Ninedots
Python
CircleCI
Amazon Web Services (AWS)