Socket
Socket
Sign inDemoInstall

Security News

Risky Biz Podcast: How Socket Goes Beyond Vulnerabilities to Tackle Modern Supply Chain Attacks in Open Source Software

In the latest Risky Biz Podcast episode, Socket CEO Feross Aboukhadijeh discussed the limitations of the National Vulnerability Database (NVD) in addressing the modern risks associated with using open source package registries.

Risky Biz Podcast: How Socket Goes Beyond Vulnerabilities to Tackle Modern Supply Chain Attacks in Open Source Software

Sarah Gooding

July 22, 2024


In the latest episode of the Risky Business podcast, host Tom Uren chatted with Socket CEO Feross Aboukhadijeh about the limitations of the National Vulnerability Database (NVD) in addressing the modern risks associated with open-source software. While the NVD is effective for tracking vulnerabilities, it often fails to account for backdoors, malware, and other malicious code found in open-source packages. This gap in coverage leaves organizations vulnerable, as many of these threats are not officially documented and, therefore, not detected by traditional vulnerability scanners.

Feross emphasized the diverse range of threats posed by malicious packages, from political protest "protestware" to sophisticated state-sponsored backdoors. Socket addresses these issues by continuously analyzing and monitoring all major open-source ecosystems in real-time. Using advanced static analysis and machine learning, Socket can detect malicious behaviors, such as data exfiltration and obfuscated code, that might not be flagged by conventional tools. This proactive approach helps identify approximately 100 supply chain attacks each week, significantly enhancing security for organizations that rely on open-source software.

They also discussed the challenges of maintaining internal package mirrors, which can inadvertently harbor and distribute malicious packages even after they have been removed from public registries. Feross explained how Socket provides solutions to mitigate these risks by integrating with internal package hosts and offering real-time alerts and remediation guidance.

Check out the full episode in the video or read the transcript below.

Subscribe to our newsletter

Get notified when we publish new security blog posts!

Try it now

Ready to block malicious and vulnerable dependencies?

Install GitHub AppBook a demo

Related posts

Back to all posts
SocketSocket SOC 2 Logo

Product

Packages

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc