Podcast Archives - Software Engineering Daily · Podcast Archives - Software Engineering Daily

Blocking Software Supply Chain Attacks with Feross Aboukhadijeh

·48 min·4 clips
Attackers predict what AI models hallucinate, then squat on those package names to execute remote code.
This episode features Feross Aboukhadijeh, founder of the security platform Socket, in conversation with host Josh Goldberg. They explore the growing threat of software supply chain attacks targeting open source dependencies. Aboukhadijeh shares his journey from creating viral projects like YouTube Instant to becoming a prominent open source maintainer. He recounts building a Flash animation website in high school using PHP and MySQL, which attracted 600,000 annual visitors. Aboukhadijeh later created YouTube Instant in three hours as a bet, leading to a viral media storm and a job offer from YouTube's CEO. His open source work includes WebTorrent, a peer-to-peer protocol now used by major clients like BitTorrent Web. Maintaining popular projects led to burnout from feeling responsible for fixing every reported GitHub issue. The discussion shifts to security, highlighting the 2017 event-stream compromise where a malicious update stole cryptocurrency from a specific Electron app. Attackers often exploit install scripts in package managers like npm to run code automatically during installation. Malicious packages can remain undetected for over 200 days, according to a USENIX security conference paper. Aboukhadijeh notes that obvious malware, like code with giant Base64 strings or environment variable exfiltration, often goes unnoticed because few developers audit their dependencies. He emphasizes the critical importance of using lock files to pin exact dependency versions, including transitive ones. The core problem is that everyone assumes someone else is vetting open source code, creating a security gap. Socket's approach involves detecting new risky capabilities in packages, such as sudden filesystem or network access. A key insight is that all code bundled into an application, regardless of origin, has access to user data and represents a risk. The viral success of simple projects like YouTube Instant underscores the value of shipping quickly over perfect engineering. The tone is conversational and educational, blending personal anecdotes with practical security lessons. This episode is ideal for software developers, open source maintainers, and security professionals concerned with dependency management. Listeners seeking highly technical deep dives or those uninterested in open source ecosystems might find it less relevant.

As heard by us

A practical look at how trusted dependencies become a supply chain risk.

Open source dependency chains take center stage here, showing how convenience in modern software can become a security liability when attackers compromise popular libraries and pass the damage downstream.

Read the full review in PlayNext →

Why you'd press play

If your build depends on packages you did not write, this conversation is worth your time.

Read the full recommendation in PlayNext →
Listen to the show on