Philipp Burckhardt

6.9K posts

Philipp Burckhardt banner
Philipp Burckhardt

Philipp Burckhardt

@burckhap

⚡Securing Software Supply Chains at @SocketSecurity (https://t.co/rjmrp0fCL0) 🔭 Scientific computing for the web via @stdlibjs (https://t.co/nJc4oxoUlD)

Pittsburgh, PA Sumali Ekim 2010
1.7K Sinusundan1.6K Mga Tagasunod
Naka-pin na Tweet
Philipp Burckhardt
Philipp Burckhardt@burckhap·
GraphMaker for easy graph building: describe in English what nodes and edges you want, and it handles the rest via OpenAI's help. Support for trees, DAGs, styling, saving in multiple formats etc. Work in progress, please send @CRGenovese and me feedback! github.com/isle-project/g…
English
1
1
4
1.4K
Philipp Burckhardt
Philipp Burckhardt@burckhap·
We identified 72 malicious Open VSX extensions linked to the GlassWorm campaign, including many cases where the malware is distributed transitively by being delilvered via covert extension packs. See below for link to our full coverage.
English
0
0
2
70
Philipp Burckhardt nag-retweet
Alexandros Kapravelos
Alexandros Kapravelos@kapravel·
We are starting a research internship program at @SocketSecurity We are particularly interested in PhD students who want to apply their research ideas in the broad space of software supply chain security and simultaneously gain industry experience and real-world impact.⬇️
English
1
8
3
1.9K
Philipp Burckhardt
Philipp Burckhardt@burckhap·
While we haven't seen major supply chain attacks hitting any of the major open-source ecosystems, the Socket Threat Research Team uncovered some fascinating and creative attack techniques worth sharing:
English
1
0
0
77
Philipp Burckhardt nag-retweet
Naugtur 💔🇺🇦
Naugtur 💔🇺🇦@naugtur·
Hey, you! Want to protect your dev machine from npm malware without changing your workflow? Try a new tool that transparently isolates npm cli in a docker container. No need to remember to do anything! Early access: github.com/lavamoat/kipuka RT for reach 😉 and help me improve
Naugtur 💔🇺🇦 tweet media
English
3
14
19
2.3K
Philipp Burckhardt
Philipp Burckhardt@burckhap·
On the @stdlibjs blog, we just published my take on @METR_Evals's surprising study: AI tools made experienced developers 19% slower (expectation: 40% faster!)🤯 I dive into the why, where AI coding tools actually help, and how I've shifted from handholding AI to async delegation.
English
1
0
2
890
Philipp Burckhardt
Philipp Burckhardt@burckhap·
Undocumented Protestware We found hidden functionality in 28+ npm packages that disables UI for Russian-language users visiting .ru or .by domains. No CVEs. No advisories. No documentation. Just behavior-based disruption quietly copied into packages and shipped to production.
English
1
0
0
35
Philipp Burckhardt
Philipp Burckhardt@burckhap·
Two major npm supply chain discoveries this week from the Socket Research Team highlight a critical gap in traditional security approaches. Both threats would slip past security tools that rely on vulnerability databases or metadata alone.
English
1
0
1
103
Ryan Petersen
Ryan Petersen@typesfast·
What’s the best history book you’ve read?
English
667
89
1.4K
950.5K
Philipp Burckhardt
Philipp Burckhardt@burckhap·
These packages, disguised as "the cheapest Cursor API," install backdoors that steal credentials and modify crucial files. In total, sw-cur, sw-cur1, and aiide-cur have been downloaded 3,200+ times before discovery. Read more on the Socket blog: socket.dev/blog/malicious…
English
0
0
0
116
Philipp Burckhardt
Philipp Burckhardt@burckhap·
🚨 With vibe coding being on everyone's minds and AI code generations seemingly becoming ubiquitous, it is not surprising that this attracts also malicious actors. Kirill Boychenko just uncovered three malicious npm packages targeting Cursor users on macOS.
English
1
0
0
49
Philipp Burckhardt
Philipp Burckhardt@burckhap·
Over the last few months, I have been picking up Cursor again after finding it not substantially improving my productivity when I tried it last year. It, and the LLMs powering AI code completions, have gotten so much better that I now really enjoy its agent workflow.
English
1
0
1
77