🚨 Shai-Hulud Strikes Again:834 Packages Compromised.Technical Analysis
Socket
Book a DemoInstallSign in
Socket
Back
Security News

Software Engineering Daily Podcast: Feross on AI, Open Source, and Supply Chain Risk

Socket CEO Feross Aboukhadijeh joins Software Engineering Daily to discuss modern software supply chain attacks and rising AI-driven security risks.

Software Engineering Daily Podcast: Feross on AI, Open Source, and Supply Chain Risk

Sarah Gooding

December 11, 2025

Socket founder and CEO Feross Aboukhadijeh joined Josh Goldberg on Software Engineering Daily to talk about how modern software teams can stay ahead of open source supply chain attacks.

Feross shared how years of watching incidents like the event-stream compromise and other package takeovers led him to start Socket, and why teams need to treat open source dependencies as their code rather than “magic from the cloud.” He talks about practical habits like using lock files, vetting new dependencies, and catching risky changes such as new network, file system, or install script behavior before they land in production.

The conversation also digs into AI-driven risk. Feross explains how companies are racing to adopt AI under board pressure, wiring agents and MCP servers into sensitive systems while leaving API tokens and config in places any compromised package could reach. Attackers are already registering package names that language models hallucinate, aiming to get pulled in by auto-generated code.

If you want to learn more about where supply chain attacks are headed and how Socket helps teams ship fast without opening the door to malware, check out the full episode below or listen to it on Software Engineering Daily.

Subscribe to our newsletter

Get notified when we publish new security blog posts!

Try it now

Ready to block malicious and vulnerable dependencies?

Install GitHub AppBook a Demo

Related posts

Back to all posts