
The Changelog: Software Development, Open Source
npm under siege (what to do about it) (Friends)
Oct 3, 2025 · 1 hr 35 min · 137.4 MB
0:00-1:35:20
Streams straight from the publisher. PodNod never proxies or re-hosts episode audio.
Over the past two months, we’ve seen some of the most serious supply chain attacks in npm history: phishing campaigns, maintainer account takeovers, and malware published to packages with billions of weekly downloads. What is going on?! What can we do about it? Our old friend, Feross Aboukhadijeh, joins us to help make sense of it all.
Changelog++ members save 2 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
- Depot – 10x faster builds? Yes please. Build faster. Waste less time. Accelerate Docker image builds, and GitHub Actions workflows. Easily integrate with your existing CI provider and dev workflows to save hours of build time.
Featuring:
- Feross Aboukhadijeh – Website, GitHub, X
- Jerod Santo – Website, GitHub, LinkedIn, Mastodon, X
- Adam Stacoviak – Website, GitHub, LinkedIn, Mastodon, X
Show Notes:
- Active supply chain attack: npm phishing campaign
- Npm phishing email targets developers with typosquat
- Nx npm packages compromised in supply chain attack
- Introducing socket firewall
- Changelog News Classifieds
Something missing or broken? PRs welcome!
Join the discussion
changelog.zulipchat.comChangelog++
changelog.comDepot
depot.devWebsite
feross.orgGitHub
github.comX
x.comWebsite
jerodsanto.netGitHub
github.comLinkedIn
linkedin.comMastodon
changelog.socialX
x.comWebsite
adamstacoviak.comGitHub
github.comLinkedIn
linkedin.comMastodon
changelog.socialX
x.comIntroducing socket firewall
socket.devChangelog News Classifieds
forms.glePRs welcome!
github.com
- 0:00Let's talk!
- 0:38Sponsor: Depot
- 2:49Feross & Friends
- 4:04The big picture
- 5:50Why now? Why this?
- 8:21Phishing maintainers!
- 11:51Not for the lulz
- 15:28Maximal profit
- 18:59The most surprising hack
- 23:03exfiltrate and extrude
- 25:44Exploiting GitHub Actions
- 29:56It all happened so fast
- 31:10How Socket discloses
- 32:30Disclosing 0days vs malware
- 34:49Scanning GitHub Actions
- 36:18GH Actions footguns
- 40:04Socket's future GH Actions feature
- 41:48Evil genius move
- 43:14What devs can do
- 47:30Staying off the bleeding edge
- 50:21How many typosquats
- 52:58How we got here
- 54:33Was it worth it?
- 57:09GitHub's responsibility
- 58:37GitHub's roadmap
- 1:03:54Why doesn't npm do this
- 1:06:17A package vetting period
- 1:08:08Publisher opt-in
- 1:12:03We figured it out!
- 1:12:36Adam goes GH Karen
- 1:15:17Codegen everything instead
- 1:20:08More companies vendoring
- 1:22:16Proxies, mirrors, options
- 1:23:22New tool! sfw
- 1:27:37The next big thing?
- 1:28:50The criteria for free
- 1:31:07sfw is a great name
- 1:31:29Bye, friends
- 1:32:34Next week on the pod