Ahmad Nassri's Avatar

Ahmad Nassri

@ahmadnassri.com

CTO @ Socket.dev

768
Followers
44
Following
26
Posts
24.07.2023
Joined
Posts Following

Latest posts by Ahmad Nassri @ahmadnassri.com

🚨 Active Shai-Hulud–Like npm Supply Chain Attack: SANDWORM_MODE
🚨 Active Shai-Hulud–Like npm Supply Chain Attack: SANDWORM_MODE YouTube video by Socket Security

Join Socket + Cloudflare in a livestream NOW discussing #SANDWORM_MODE the Shai-Hulud-Style npm Worm Hijacking CI Workflows and Poisoning AI Toolchains

www.youtube.com/watch?v=OQ6w...

20.02.2026 21:31 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
🚨 Active Shai-Hulud–Like npm Supply Chain Attack: SANDWORM_MODE
🚨 Active Shai-Hulud–Like npm Supply Chain Attack: SANDWORM_MODE YouTube video by Socket Security

Join @socket.dev + @cloudflare.social in a livestream NOW discussing #SANDWORM_MODE the Shai-Hulud-Style npm Worm Hijacking CI Workflows and Poisoning AI Toolchains

www.youtube.com/watch?v=OQ6w...

20.02.2026 21:30 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

If you think your organization may have been affected or would like help assessing your exposure, please reach out and we will help.

20.02.2026 19:02 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

If you are a @socket.dev customer, these packages are automatically blocked in the environments where Socket is deployed (and have been blocked since our initial confirmation ~36 hours ago).

20.02.2026 19:02 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

The campaign is designed to steal credentials from developer workstations and CI environments, inject malicious GitHub Actions workflows for self-propagation, poison AI toolchains via rogue MCP servers, and exfiltrate LLM API keys.

20.02.2026 19:02 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

The @socket.dev team caught super early signals of this attack campaign leading to preemptive shutdown! proud of the team and our advanced threat detection engine! πŸ’ͺ

Thankful for the rapid response and takedown @npmjs.bsky.social @github.com @cloudflare.social πŸ™

#shaihulud #SANDWORM_MODE

20.02.2026 18:25 πŸ‘ 12 πŸ” 4 πŸ’¬ 2 πŸ“Œ 0

Incoming news. Stay tuned.

20.02.2026 17:03 πŸ‘ 3 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Post image

Really cool to see @npmjs.bsky.social featuring more security information on package pages, including a link to Socket's analysis! 🀩

Here's what you'll find when you click through β†’

socket.dev/blog/socket-... #NodeJS #JavaScript

19.02.2026 03:13 πŸ‘ 9 πŸ” 4 πŸ’¬ 0 πŸ“Œ 1
Preview
Malicious Chrome Extension Steals Meta Business Manager Expo... Chrome extension CL Suite by @CLMasters neutralizes 2FA for Facebook and Meta Business accounts while exfiltrating Business Manager contact and analyt...

New Research: Malicious Chrome extension targets Meta Business Suite/Facebook Business Manager, steals TOTP 2FA seeds + codes, and exfiltrates Business Manager exports (People + analytics).

Full analysis: socket.dev/blog/malicio...

13.02.2026 02:55 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸš€ Socket Launch Week Day 3: We’re launching supply chain attack campaign tracking in the Socket dashboard!

21.01.2026 21:40 πŸ‘ 3 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Video thumbnail

Add this episode to your podcast listening queue during the holidays. 🎧

Socket CTO @ahmadnassri.com talks through practical AI coding workflows, where AI actually helps teams today, and why the biggest shifts are being driven by economics.

socket.dev/blog/enginee...

24.12.2025 05:59 πŸ‘ 2 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

Congrats @docker.com! This is the right move for the ecosystem.

In case you missed this detail: with Docker Hardened Images teams get secure application dependencies by default. @socket.dev Firewall is built in.

17.12.2025 19:03 πŸ‘ 9 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0
Preview
Socket Firewall Now Available in Docker Hardened Images - So... Socket Firewall Free is now bundled into Docker Hardened Images, adding build-time and dependency-install supply chain protection on top of hardened b...

πŸš€ Big News! Docker Hardened Images are now free! We’re partnering with @docker.com to bundle Socket Firewall into supported images, adding supply chain protection during dependency installs and builds.

Details β†’ socket.dev/blog/socket-...

17.12.2025 16:38 πŸ‘ 5 πŸ” 2 πŸ’¬ 0 πŸ“Œ 1
Preview
Socket Firewall Now Available in Docker Hardened Images - So... Socket Firewall Free is now bundled into Docker Hardened Images, adding build-time and dependency-install supply chain protection on top of hardened b...

We’re partnering with @docker.com to make software development safer for everyone!

Socket Firewall Free is now bundled into Docker Hardened Images, adding build-time and dependency-install supply chain protection for @nodejs.org, @python.org, and @rust-lang.org

socket.dev/blog/socket-...

17.12.2025 15:39 πŸ‘ 6 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
The Nightmare Before Deployment - Socket Season’s greetings from Socket, and here’s to a calm end of year: clean dependencies, boring pipelines, no surprises.

🎁 The Nightmare Before Deployment

socket.dev/blog/supply-...

16.12.2025 20:51 πŸ‘ 4 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0

left some thoughts in the thread, moving away from postinstall is definitely a step in the right direction, but it will not alleviate security scanning concerns.

03.12.2025 21:51 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Video thumbnail

πŸŽ™οΈ Why great products don't always win: Socket CEO @feross.bsky.social breaks down a hard truth for technical founders in this conversation with Vlad Kachur on scaling a security company.

Check out the full interview β†’ socket.dev/blog/scaling... #appsec #infosec

02.12.2025 16:25 πŸ‘ 1 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
Shai Hulud Strikes Again (v2) - Socket Another wave of Shai-Hulud campaign has hit npm with more than 500 packages and 700+ versions affected.

Shai-Hulud DΓ©jΓ  vu!

🚨 new wave of supply chain attacks hits npm, impacting widely used packages from AsyncAPI, ENS, Postman, PostHog, and Zapier.

socket.dev/blog/shai-hu...

24.11.2025 16:00 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

πŸš€ Big news for JavaScript teams: Socket now supports Bun and vlt in beta.

You no longer have to choose between innovation and security. Commit a bun.lock or vlt-lock.json and Socket gives you full supply chain protection.

19.11.2025 17:21 πŸ‘ 10 πŸ” 5 πŸ’¬ 1 πŸ“Œ 0
Post image

Launch Week Day 3: We're announcing beta support for
@bun.sh and @vlt.sh package managers in Socket! πŸŽ‰

Developers using emerging JavaScript package managers can now rely on Socket for full supply chain security, dependency graph analysis, and accurate SBOMs.

19.11.2025 17:31 πŸ‘ 5 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0
Preview
How Enterprise Security Is Adapting to AI-Accelerated Threat... Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Check out Socket CTO @ahmadnassri.com
at @workos.bsky.social' Enterprise Ready Conf: Ahmad joined a panel discussing how enterprise security is adapting, as AI speeds up both software development and attacks targeting developer machines. socket.dev/blog/how-ent...

05.11.2025 18:48 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

soon inshallah.

01.11.2025 19:27 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

nothing beats a Syrian breakfast 🀀

@ Damaski Palace maps.app.goo.gl/NWZatN3mgves...

01.11.2025 16:09 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

πŸš€ Socket Launch Week Day 5!

Malicious packages are infiltrating development environments before they ever reach production.

Today we're answering these threats with the release of Socket Firewall Enterprise: configurable, enterprise-grade protection for modern package ecosystems.

24.10.2025 18:27 πŸ‘ 2 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Announcing Experimental Malware Scanning for the Hugging Face Ecosystem
Announcing Experimental Malware Scanning for the Hugging Face Ecosystem YouTube video by Socket Security

1️⃣
AI models aren’t just math -- they’re code.
And just like npm or PyPI, they can get hacked.

Today we’re launching malware scanning for the Hugging Face ecosystem. πŸ€–πŸ”

Socket can now detect backdoors and malicious payloads inside AI models themselves.

πŸ‘‡

www.youtube.com/watch?v=9FQy...

20.10.2025 16:21 πŸ‘ 11 πŸ” 6 πŸ’¬ 2 πŸ“Œ 0

for better security: I use 1password cli with direnv to dynamically load env values (ssh keys, tokens, secrets, etc ...)

AWS outage -> 1password thinks it's offline -> can't run anything locally which requires secretsπŸ₯²

20.10.2025 16:45 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Recognition for Sarah! So deserved! @sarahgooding.bsky.social

16.10.2025 14:50 πŸ‘ 9 πŸ” 4 πŸ’¬ 2 πŸ“Œ 0
Post image

Join me next week at the @workos.bsky.social Enterprise Ready Conf. will be speaking on a panel on all things security & how developers can take back control of their software supply chain.

If you're attending, lchat with me & the @socket.dev team IRL!

enterprise-ready.com

15.10.2025 15:16 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Socket Integrates With Bun 1.3’s Security Scanner API - Sock... Socket now integrates with Bun 1.3’s Security Scanner API to block risky packages at install time and enforce your organization’s policies in local de...

@bun.sh users can now install any package with confidence, knowing that @socket.dev got their back!

Free from malicious packages, typosquatting, and other supply chain attacks.

socket.dev/blog/socket-...

10.10.2025 22:36 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
175 Malicious npm Packages Host Phishing Infrastructure Targ... 175 malicious npm packages (26k+ downloads) used unpkg CDN to host redirect scripts for a credential-phishing campaign targeting 135+ organizations wo...

β†’ 175 malicious packages
β†’ 135+ targeted organizations
β†’ 26,800+ downloads
β†’ Fully automated victim generation
β†’ Pre-filled credential forms
β†’ Complete PyInstaller toolkit included

Technical deep-dive with full IOCs: πŸ‘‰ socket.dev/blog/175-mal...

10.10.2025 12:34 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0