Sign In

Feross Aboukhadijeh

Founder & CEO of Socket, Open Source Developer

Feross Aboukhadijeh is the Founder and CEO of Socket, a company focused on enhancing security and privacy in software development, particularly concerning open-source software. He is based in the San Francisco Bay Area and has a strong background in technology and open-source contributions.

Background and Career

Feross graduated from Stanford University and has over a decade of experience in open-source software development. He is known for creating several widely used JavaScript packages and has previously worked at notable companies, including Intel, Facebook, and Quora. His early work includes developing PeerCDN, a pioneering peer-to-peer content delivery network.145

At Socket, Feross leads efforts to help developers and security teams manage and secure open-source dependencies, aiming to streamline the software supply chain while mitigating security risks. The platform is designed to assist organizations in auditing and managing their open-source software effectively.234

Contributions and Vision

Feross is passionate about improving the developer experience and addressing security challenges in software development. He emphasizes the importance of curiosity, persistence, and a love for technology as key traits for success in the tech industry. His vision for the future includes a more open technology landscape that prioritizes long-term impact over short-term gains.12

In addition to his role at Socket, Feross serves as a lecturer at Stanford, teaching courses on web security, further solidifying his commitment to education and the tech community.25

Highlights

Apr 30 · twitter

This is not what I expected.

Apr 29 · twitter

🚨 Active supply chain attack hitting SAP’s CAP ecosystem on npm.

Four packages tied to SAP’s Cloud Application Programming Model just shipped versions with a new preinstall script that downloads and executes a platform-specific binary. These packages never required this before today.

Affected versions:

[email protected] • @​cap-js/[email protected] • @​cap-js/[email protected] • @​cap-js/[email protected]

Combined, these packages see 570K+ weekly downloads. @​cap-js/db-service and @​cap-js/sqlite alone account for ~510K of that. If you’re building on SAP BTP or using MTA deployment pipelines, check your lockfiles now.

The compromised versions added a preinstall script that acts as a bootstrapper: it downloads a Bun ZIP from GitHub Releases, extracts it, and immediately executes the binary. It follows HTTP redirects without validating the destination. On Windows, it invokes PowerShell with -ExecutionPolicy Bypass.

All four versions were published within a ~2.5 hour window this morning (April 29, UTC). At least one version (@​cap-js/[email protected]) has already been unpublished.

Socket flagged the malicious behavior and is continuing to investigate. If you’re affected:

• Do not install the affected versions • Pin to previous known-good versions • Rotate any credentials or tokens exposed in build/dev environments • Review CI/CD logs for unexpected network calls or binary execution

Developing story…

🚨 Active supply chain attack hitting SAP’s CAP ecosystem on npm.

Four packages tied to SAP’s Cloud
Feross Aboukhadijeh, Founder and CEO of Socket.dev, a startup ...
Feross Aboukhadijeh, Founder and CEO of Socket.dev, a startup ...
Dec 13 · Fortune
Socket - Fortune
Socket - Fortune
Nov 25 · 4imag.com
Meet the talent: Feross Aboukhadijeh, Founder and CEO of Socket
Meet the talent: Feross Aboukhadijeh, Founder and CEO of Socket
Aug 31 · Built In
Is a Decentralized Internet on the Horizon? - Built In

Related Questions

What inspired Feross Aboukhadijeh to start Socket?
How does Socket improve security and privacy on the web?
What are some recent supply chain attacks Feross has discussed?
How did Feross transition from being a developer to a CEO?
What makes Socket different from other security tools?
Feross Aboukhadijeh
Feross Aboukhadijeh, photo 1
Feross Aboukhadijeh, photo 2
Add to my network

Experience

Founder & CEO at Socket (June 2020 - Present)
Visiting Lecturer at Stanford University, Open Source Developer at Standard JS, WebTorrent, Brave Software, BitMidi, Software Engineer at Yahoo! Inc., Founder & CEO at PeerCDN

Education

Teaching Assistant for CS110: Principles of Computer Systems at Stanford University (2018 - 2020), Software Engineer Intern at Quora (2011), Software Engineer Intern at Facebook (2010), Web Developer & Videographer at Intel Corporation (2007 - 2008)

Location

San Francisco Bay Area