Socket reposted this
The attack didn't start with code. It started with a collaboration email. The maintainer of one of the most widely used HTTP libraries in JavaScript, the de facto standard, got a note from what looked like a legitimate company. They invited him to a Slack channel. For nearly a month they worked with him: real conversations, real ideas, real help for his project. Then a Microsoft Teams call cut out mid-meeting and a prompt appeared saying Teams was out of date, click this file to update. The file was malware. Several of us at Socket received the same lure. I can't take credit for not falling for it. I never saw the email. One of the best phishing defenses, it turns out, is being too busy to read your inbox. Not a strategy I would recommend. :) This is what supply chain attacks look like now: patient, targeted, and aimed at the human rather than the code. Compromise one maintainer and you reach every application that depends on the library, increasingly including the AI agents and coding tools that pull it in by default. You can't train your way out of a month-long social engineering campaign. You have to assume compromise will happen and catch malicious code at the moment it enters your dependencies. That's what we're building at Socket. From my conversation with Anne Dwane on the Village Global podcast.