<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: feross</title><link>https://news.ycombinator.com/user?id=feross</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 18 Apr 2026 05:33:37 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=feross" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Axios Maintainer Confirms Social Engineering Attack Behind NPM Compromise]]></title><description><![CDATA[
<p>Article URL: <a href="https://socket.dev/blog/axios-maintainer-confirms-social-engineering-behind-npm-compromise">https://socket.dev/blog/axios-maintainer-confirms-social-engineering-behind-npm-compromise</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47622506">https://news.ycombinator.com/item?id=47622506</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 03 Apr 2026 02:08:34 +0000</pubDate><link>https://socket.dev/blog/axios-maintainer-confirms-social-engineering-behind-npm-compromise</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=47622506</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47622506</guid></item><item><title><![CDATA[The Hidden Blast Radius of the Axios Compromise]]></title><description><![CDATA[
<p>Article URL: <a href="https://socket.dev/blog/hidden-blast-radius-of-the-axios-compromise">https://socket.dev/blog/hidden-blast-radius-of-the-axios-compromise</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47606999">https://news.ycombinator.com/item?id=47606999</a></p>
<p>Points: 6</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 01 Apr 2026 21:53:00 +0000</pubDate><link>https://socket.dev/blog/hidden-blast-radius-of-the-axios-compromise</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=47606999</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47606999</guid></item><item><title><![CDATA[Trivy Supply Chain Attack Expands to Compromised Docker Images]]></title><description><![CDATA[
<p>Article URL: <a href="https://socket.dev/blog/trivy-docker-images-compromised">https://socket.dev/blog/trivy-docker-images-compromised</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47485065">https://news.ycombinator.com/item?id=47485065</a></p>
<p>Points: 5</p>
<p># Comments: 3</p>
]]></description><pubDate>Mon, 23 Mar 2026 03:02:45 +0000</pubDate><link>https://socket.dev/blog/trivy-docker-images-compromised</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=47485065</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47485065</guid></item><item><title><![CDATA[New comment by feross in "Trivy ecosystem supply chain temporarily compromised"]]></title><description><![CDATA[
<p>Lots more technical research about the actual attack and how it worked here: <a href="https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise" rel="nofollow">https://socket.dev/blog/trivy-under-attack-again-github-acti...</a><p>Disclosure: I’m the founder of Socket.</p>
]]></description><pubDate>Sun, 22 Mar 2026 14:54:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=47478151</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=47478151</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47478151</guid></item><item><title><![CDATA[Malicious NPM Packages Use Pastebin Steganography to Deploy Credential Stealer]]></title><description><![CDATA[
<p>Article URL: <a href="https://socket.dev/blog/stegabin-26-malicious-npm-packages-use-pastebin-steganography">https://socket.dev/blog/stegabin-26-malicious-npm-packages-use-pastebin-steganography</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47185535">https://news.ycombinator.com/item?id=47185535</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 27 Feb 2026 21:00:10 +0000</pubDate><link>https://socket.dev/blog/stegabin-26-malicious-npm-packages-use-pastebin-steganography</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=47185535</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47185535</guid></item><item><title><![CDATA[Malicious Go "Crypto" Module Steals Passwords and Deploys Rekoobe Backdoor]]></title><description><![CDATA[
<p>Article URL: <a href="https://socket.dev/blog/malicious-go-crypto-module-steals-passwords-and-deploys-rekoobe-backdoor">https://socket.dev/blog/malicious-go-crypto-module-steals-passwords-and-deploys-rekoobe-backdoor</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47173960">https://news.ycombinator.com/item?id=47173960</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 26 Feb 2026 23:42:35 +0000</pubDate><link>https://socket.dev/blog/malicious-go-crypto-module-steals-passwords-and-deploys-rekoobe-backdoor</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=47173960</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47173960</guid></item><item><title><![CDATA[Shai-Hulud-Style NPM Worm Hijacks CI Workflows and Poisons AI Toolchains]]></title><description><![CDATA[
<p>Article URL: <a href="https://socket.dev/blog/sandworm-mode-npm-worm-ai-toolchain-poisoning">https://socket.dev/blog/sandworm-mode-npm-worm-ai-toolchain-poisoning</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47093380">https://news.ycombinator.com/item?id=47093380</a></p>
<p>Points: 8</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 20 Feb 2026 20:22:35 +0000</pubDate><link>https://socket.dev/blog/sandworm-mode-npm-worm-ai-toolchain-poisoning</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=47093380</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47093380</guid></item><item><title><![CDATA[First Brands Did Some Round Trips]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.bloomberg.com/opinion/newsletters/2026-01-29/first-brands-did-some-round-trips">https://www.bloomberg.com/opinion/newsletters/2026-01-29/first-brands-did-some-round-trips</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46849357">https://news.ycombinator.com/item?id=46849357</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 01 Feb 2026 21:05:17 +0000</pubDate><link>https://www.bloomberg.com/opinion/newsletters/2026-01-29/first-brands-did-some-round-trips</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=46849357</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46849357</guid></item><item><title><![CDATA[15 Years of Blogging]]></title><description><![CDATA[
<p>Article URL: <a href="https://nolanlawson.com/2026/02/01/15-years-of-blogging/">https://nolanlawson.com/2026/02/01/15-years-of-blogging/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46849246">https://news.ycombinator.com/item?id=46849246</a></p>
<p>Points: 2</p>
<p># Comments: 1</p>
]]></description><pubDate>Sun, 01 Feb 2026 20:50:38 +0000</pubDate><link>https://nolanlawson.com/2026/02/01/15-years-of-blogging/</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=46849246</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46849246</guid></item><item><title><![CDATA[When will CSS Grid Lanes arrive?]]></title><description><![CDATA[
<p>Article URL: <a href="https://webkit.org/blog/17758/when-will-css-grid-lanes-arrive-how-long-until-we-can-use-it/">https://webkit.org/blog/17758/when-will-css-grid-lanes-arrive-how-long-until-we-can-use-it/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46841794">https://news.ycombinator.com/item?id=46841794</a></p>
<p>Points: 50</p>
<p># Comments: 27</p>
]]></description><pubDate>Sat, 31 Jan 2026 23:02:45 +0000</pubDate><link>https://webkit.org/blog/17758/when-will-css-grid-lanes-arrive-how-long-until-we-can-use-it/</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=46841794</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46841794</guid></item><item><title><![CDATA[2026.05: The Chip Fly in the AI Ointment]]></title><description><![CDATA[
<p>Article URL: <a href="https://stratechery.com/2026/the-chip-fly-in-the-ai-ointment/">https://stratechery.com/2026/the-chip-fly-in-the-ai-ointment/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46841681">https://news.ycombinator.com/item?id=46841681</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 31 Jan 2026 22:47:06 +0000</pubDate><link>https://stratechery.com/2026/the-chip-fly-in-the-ai-ointment/</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=46841681</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46841681</guid></item><item><title><![CDATA[Put a Pin in It]]></title><description><![CDATA[
<p>Article URL: <a href="https://signal.org/blog/pinned-messages/">https://signal.org/blog/pinned-messages/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46841458">https://news.ycombinator.com/item?id=46841458</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 31 Jan 2026 22:17:47 +0000</pubDate><link>https://signal.org/blog/pinned-messages/</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=46841458</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46841458</guid></item><item><title><![CDATA[Building a browser API in one shot]]></title><description><![CDATA[
<p>Article URL: <a href="https://nolanlawson.com/2026/01/31/building-a-browser-api-in-one-shot/">https://nolanlawson.com/2026/01/31/building-a-browser-api-in-one-shot/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46841347">https://news.ycombinator.com/item?id=46841347</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 31 Jan 2026 22:02:23 +0000</pubDate><link>https://nolanlawson.com/2026/01/31/building-a-browser-api-in-one-shot/</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=46841347</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46841347</guid></item><item><title><![CDATA[Kimwolf Botnet Lurking in Corporate, Govt. Networks]]></title><description><![CDATA[
<p>Article URL: <a href="https://krebsonsecurity.com/2026/01/kimwolf-botnet-lurking-in-corporate-govt-networks/">https://krebsonsecurity.com/2026/01/kimwolf-botnet-lurking-in-corporate-govt-networks/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46841219">https://news.ycombinator.com/item?id=46841219</a></p>
<p>Points: 19</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 31 Jan 2026 21:47:04 +0000</pubDate><link>https://krebsonsecurity.com/2026/01/kimwolf-botnet-lurking-in-corporate-govt-networks/</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=46841219</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46841219</guid></item><item><title><![CDATA[Michael Ovitz: The Business of Relationships]]></title><description><![CDATA[
<p>Article URL: <a href="https://fs.blog/knowledge-project-podcast/michael-ovitz/">https://fs.blog/knowledge-project-podcast/michael-ovitz/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46841074">https://news.ycombinator.com/item?id=46841074</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 31 Jan 2026 21:32:27 +0000</pubDate><link>https://fs.blog/knowledge-project-podcast/michael-ovitz/</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=46841074</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46841074</guid></item><item><title><![CDATA[Best of Moltbook]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.astralcodexten.com/p/best-of-moltbook">https://www.astralcodexten.com/p/best-of-moltbook</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46840938">https://news.ycombinator.com/item?id=46840938</a></p>
<p>Points: 92</p>
<p># Comments: 37</p>
]]></description><pubDate>Sat, 31 Jan 2026 21:16:46 +0000</pubDate><link>https://www.astralcodexten.com/p/best-of-moltbook</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=46840938</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46840938</guid></item><item><title><![CDATA[GlassWorm Loader Hits Open VSX via Developer Account Compromise]]></title><description><![CDATA[
<p>Article URL: <a href="https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise">https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46840808">https://news.ycombinator.com/item?id=46840808</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 31 Jan 2026 21:01:50 +0000</pubDate><link>https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=46840808</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46840808</guid></item><item><title><![CDATA[Ads in ChatGPT, Why OpenAI Needs Ads, the Long Road to Instagram]]></title><description><![CDATA[
<p>Article URL: <a href="https://stratechery.com/2026/ads-in-chatgpt-why-openai-needs-ads-the-long-road-to-instagram/">https://stratechery.com/2026/ads-in-chatgpt-why-openai-needs-ads-the-long-road-to-instagram/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46697213">https://news.ycombinator.com/item?id=46697213</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 20 Jan 2026 20:18:15 +0000</pubDate><link>https://stratechery.com/2026/ads-in-chatgpt-why-openai-needs-ads-the-long-road-to-instagram/</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=46697213</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46697213</guid></item><item><title><![CDATA[Turbopack: Building faster by building less]]></title><description><![CDATA[
<p>Article URL: <a href="https://nextjs.org/blog/turbopack-incremental-computation">https://nextjs.org/blog/turbopack-incremental-computation</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46696111">https://news.ycombinator.com/item?id=46696111</a></p>
<p>Points: 47</p>
<p># Comments: 23</p>
]]></description><pubDate>Tue, 20 Jan 2026 18:49:20 +0000</pubDate><link>https://nextjs.org/blog/turbopack-incremental-computation</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=46696111</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46696111</guid></item><item><title><![CDATA[2026.03: Technology Doings]]></title><description><![CDATA[
<p>Article URL: <a href="https://stratechery.com/2026/technology-doings/">https://stratechery.com/2026/technology-doings/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46650801">https://news.ycombinator.com/item?id=46650801</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 16 Jan 2026 19:17:35 +0000</pubDate><link>https://stratechery.com/2026/technology-doings/</link><dc:creator>feross</dc:creator><comments>https://news.ycombinator.com/item?id=46650801</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46650801</guid></item></channel></rss>