Product, growth, startups. Cofounder & Chief Product Officer @safetycli. Prev. Amazon EventBridge @awscloud, @kickstarter & Co-founder @Huzza_Live.

Joined April 2008
1,117 Photos and videos
Or just getsafety.com and we’ll scan every machine in your org. to detect the malicious package (and many others!) for you.
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux. The file name transformers.pyz appears deliberately chosen to mimic the widely used Hugging Face Transformers library and blend into ML/dev environments. The main payload is a credential stealer, but it also includes country-aware logic; it avoids Russian-language environments and contains a geo fenced destructive branch that has 1-in-6 chance of executing rm -rf / when the system appears to be in Israel or Iran. To mitigate this threat: isolate affected Linux hosts, block 83[.]142[.]209[.]194, hunt for /tmp/transformers.pyz, pgmonitor[.]py, and pgsql-monitor.service, and rotate exposed credentials.
2
216
This is why the only viable solution to software supply chain security MUST protect the developer workstation. That is now the single most vulnerable part of our entire industry. You have to be constantly scanning the dev endpoint, like we are @safetycli, to detect and protect.
The most insane long game hack of all time! North Korea built an entire trading firm Conference passes In-person meetings Multiple countries Half a year of Telegram messages and working sessions Even $1M of their own capital deposited to look legitimate Then when all the pieces were in place they stole $280M Drift just released the full incident background and it’s wild! Fall 2025: A "quant trading firm" approaches contributors of Drift at a major conference. They Follow up in person across multiple countries. Technically fluent. Verifiable backgrounds. Typical trust building stuff. December-March: They onboard a real Ecosystem Vault and attend working sessions They even deposit $1M to further build ‘trust’ The long con had set in and by early 2026, these weren't strangers anymore They had now built a 6-month working relationship Then they share some repos which is routine stuff The attack vector: a VSCode/Cursor vulnerability flagged by the security community throughout late 2025. Opening a file was enough. Silent code execution. No prompt. No warning. Nothing. The moment the exploit fired, every Telegram message and trace of malware was scrubbed clean No record or trace left Every team managing meaningful TVL is a target and no one is safe from professional jobs such as this Six months of infiltration and a trusted relationship, not just a sketchy email link The bug is patched but the real attack vector was the relationship and patience How do you protect against that? 🤯
2
3
283
Nick Smit retweeted
My job has changed, but not that much.
1
4
784
Nick Smit retweeted
2 Dec 2025
It's here!! This is the one I have been talking about! AWS Lambda Durable Functions are now officially out. If you want to see a deep dive of this, My buddy Michael Gasch (one of the PMs behind the magic) and I are presenting this on Wednesday. The catalog is getting updated, but watch for CNS380. aws.amazon.com/blogs/aws/bui…
10
25
177
13,940
16 Jul 2025
Fantastic to see logging for Amazon EventBridge launched! It took a while, but this will make it significantly easier to debug what's happening in your event bus. Congrats to the team!
15 Jul 2025
Game changing launch for Amazon EventBridge timed with the New York summit (where EventBridge was launched 6 years ago)! EventBridge now supports logging to CloudWatch, S3, and Firehose, giving you a new level of visibility across your applications. aws.amazon.com/blogs/aws/mon…
1
5
16
1,228
Nick Smit retweeted
New blog post, with some career advice: brooker.co.za/blog/2025/06/2…

8
33
219
23,782
28 Apr 2025
I’m at #RSAC2025 this week! If you’re also in town, let me know — I’d love to say hi!
7
351
18 Apr 2025
Upgrading from 18GB to 64GB MBP is such a massive quality of life improvement. I've gone from always feeling constrained around what I open or leave open, to instead feeling an unconstrained abundance. All the Firefox tabs. All the Docker containers. All the IDEs.
1
3
265
7 Apr 2025
Our research team @safetycli found a NPM package published by a large payment processor ($80B/year) that leaks credit card details to an ngrok endpoint. An unfortunate example of how a legitimate actor can compromise your software supply chain. getsafety.com/blog-posts/pay…
2
1
3
874
27 Feb 2025
I’ve had three separate sales calls this week from @SeamlessAI. This despite me having received confirmation of do-not-contact from them. Where are we at with the laws around repercussions for this? If I have documented evidence of them contacting me after opt-out, what can I do?
1
2
407
12 Mar 2025
@SeamlessAI I've just had another call today from Sam!
1
115
1 Mar 2025
This. I’ve been doing this with @safetycli and it’s such a powerful way to communicate ideas and features. Feels like a new super power - I love it!
1 Mar 2025
The future of product management is going to be building actual working prototypes of your ideas with AI in the time it used to take to write a PRD. Then, later it will be building the production code too in that amount of time.
2
350
Nick Smit retweeted
Replying to @nickste
1
2
141
25 Feb 2025
I'm keen to learn what folks like and dislike about reachability analysis in your vulnerability management tools? Any opportunities to do something better? Missing features of functionality? Integrations? Annoyances? Let me know!
2
1
414
Nick Smit retweeted
Added some new functionality to the EventBridge integration with EventCatalog. You can now ⭐️ Import schemas directly into your services and domains from schema discovery (if enabled) ⭐️ Import schemas from custom schema registry into EventCatalog ⭐️ Add semantic meaning to your events. Help your developers understand what the events are (beyond just a schema). ⭐️ Download code bindings for Java, TypeScript and .NET from your schema. eventcatalog.dev/integration…
4
7
721
4 Feb 2025
This feels like an under-appreciated EventBridge launch: aws.amazon.com/about-aws/wha…. The team have documented *every* event emitted by an AWS service (docs.aws.amazon.com/eventbri…) and made it easy to build rules from them. Schemas for each next?
2
7
34
1,760
Nick Smit retweeted
This is AWESOME!! EventBridge now delivers events to cross-account targets directly, without having to send them to the default bus in the target account first. More details here: aws.amazon.com/about-aws/wha… #aws #serverless #eventbridge
3
28
185
8,448
23 Dec 2024
This is a solid improvement. More going on under the hood to make this work well than you’d expect.
Amazon EventBridge announces API destinations proactive OAuth token refresh Amazon EventBridge API destinations now support proactive OAuth token refresh for public and private OAut... aws.amazon.com/about-aws/wha…
13
1,100