🚀 DAY 3 OF LAUNCH WEEK: Introducing Webhook Events for Pull Request Scans.Learn more
Socket
Book a DemoInstallSign in
Socket
Back
Security News

PodRocket Podcast: Inside the Recent npm Supply Chain Attacks

Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.

PodRocket Podcast: Inside the Recent npm Supply Chain Attacks

Sarah Gooding

October 2, 2025

Socket CEO Feross Aboukhadijeh recently joined LogRocket's PodRocket podcast to discuss the unprecedented wave of npm supply chain attacks that have hit the JavaScript ecosystem over the past few months: from phishing campaigns targeting maintainers to the Shai-Hulud worm that's affected more than 500 packages.

In this episode:

  • npm supply chain attacks explained - How attackers compromised high-profile packages with billions of weekly downloads
  • Novel attack vectors - GitHub Actions misconfigurations and how attackers weaponized AI tools like Claude and Gemini to scan for secrets
  • The install scripts problem - Why they're so dangerous and the limitations of simply banning them
  • The npm mindset shift developers need to make - Understanding what you're really doing when you run npm install
  • Will there be a chilling effect on upgrades? - Navigating the tradeoffs between security vulnerabilities and supply chain attacks
  • Smarter approaches to dependency management - Practical steps you can take today to protect your projects

This is essential listening for any JavaScript developer concerned about supply chain security in 2025. Check out the video below.

Subscribe to our newsletter

Get notified when we publish new security blog posts!

Try it now

Ready to block malicious and vulnerable dependencies?

Install GitHub AppBook a Demo

Related posts

Back to all posts