@SocketSecurity

Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. 👀 @npm_malware

Joined November 2021
Today is a big day for Socket. nitter.cf/feross/status/20571192…
Today is a big day for @SocketSecurity. We just raised a $60M Series C at a $1B valuation, led by @ThriveCapital with participation from @a16z, @AbstractVC, and @CapitalOne Ventures. Total funding is now $125M. Four years ago, we started Socket because open source dependencies were flowing into production faster than anyone could vet them. AI has massively accelerated that. Code is being written, shipped, and deployed before any human reads it. Security has to operate at that same speed. One data point from Thrive's diligence that I keep coming back to: they first discovered Socket because @cursor_ai, @OpenAI, and @AnthropicAI all independently told them it was the most important security tool they'd adopted for AI-driven development. Three of the most sophisticated AI companies converging on the same vendor unprompted. Since our Series B, Socket has grown to more than 20,000 organizations, protecting over 1.5 million repositories and blocking more than 1,000 supply chain attacks every week. The team is now over 100 people. Three out of five FAANG companies are Socket customers. So are the companies building the most ambitious AI products: @AnthropicAI, @cursor_ai, @xai, @figma, @vercel, @Replit, @scale_AI, @GustoHQ, @Mercadolibre, and @cribl_io, alongside Fortune 100s in financial services and global media. What we've shipped since the last round: • Socket Firewall blocks malicious packages at install time, before they reach a developer's laptop or CI pipeline. Free for everyone. • Reachability analysis via our acquisition of Coana, eliminating 50-80% of irrelevant vulnerability alerts by focusing only on CVEs that are actually exploitable. • Socket Certified Patches for remediating exploitable CVEs in seconds without waiting on upstream maintainers. • Coverage extending to browser extensions, editor extensions, MCP servers, and AI tools via our acquisition of @secureannex. When the Axios compromise hit, our detection systems flagged the malicious dependency within six minutes. Within 24 hours, more than 2,000 organizations onboarded to Socket to block it. Where the funding goes: deeper investment in Firewall, massively expanding Certified Patches, moving protection closer to every point of install across the developer toolchain, and new product launches pushing Socket into a category we haven't entered before. We're hiring across engineering, sales, customer success, and threat intel. ❤️ Thank you to our customers, investors, and the open-source community for your support. Together, we’re making software safer for everyone.
4
6
2
104
36,338
Open source’s next chapter might be a thousand slightly different versions of the same software. socket.dev/blog/oj-vite-rust
3
4
14
2,519
Socket retweeted
Compromised MemOS packages on npm and PyPI spread cross-platform malware that steals developer credentials and may use stolen tokens to compromise more packages, @SocketSecurity reported. #cybersecurity #CISO #infosec bit.ly/4hdOXRQ
1
1
5
1,770
Socket retweeted
Compromised MemOS packages on npm and PyPI spread cross-platform malware that steals developer credentials and may use stolen tokens to compromise more packages, @SocketSecurity reported. #cybersecurity #CISO #infosec bit.ly/4hdOXRQ
1
2
4
2,252
Open source’s next chapter might be a thousand slightly different versions of the same software. socket.dev/blog/oj-vite-rust
3
4
14
2,519
Maintainers spend countless hours keeping the open source projects we all rely on secure. Too often, that work is unpaid. Socket is proud to join @openjsf's new Security Stewardship Program to help fund the researchers and maintainers protecting Node.js. socket.dev/blog/openjs-nodej…
3
14
1,901
Socket retweeted
Absolutely crazy that these two GitHub Actions which were quarantined could be reactivated with the malware still armed. Many of the these workflows run on a cron without any true repository activity trigging them.
3
7
2,011
‼️ Mini Shai-Hulud came back without a new attacker update. Two compromised GitHub Actions became reachable again while their tags still pointed to malicious commits, letting downstream workflows resume executing the credential stealer. 🔗 Here's how the attack reactivated: thehackernews.com/2026/09/co…
7
20
1
78
38,111
Socket retweeted
Compromised MemOS packages on npm and PyPI spread cross-platform malware that steals developer credentials and may use stolen tokens to compromise more packages, @SocketSecurity reported. #cybersecurity #CISO #infosec bit.ly/4hdOXRQ
2
3
6
2,506
Socket retweeted
Absolutely crazy that these two GitHub Actions which were quarantined could be reactivated with the malware still armed. Many of the these workflows run on a cron without any true repository activity trigging them.
🚨 Two GitHub Actions compromised in May’s Mini Shai-Hulud campaign are running malware again. The repositories were re-enabled with malicious release tags intact, putting thousands of downstream repositories at risk. socket.dev/blog/mini-shai-hu…
5
1
15
7,217
🚨 Two GitHub Actions compromised in May’s Mini Shai-Hulud campaign are running malware again. The repositories were re-enabled with malicious release tags intact, putting thousands of downstream repositories at risk. socket.dev/blog/mini-shai-hu…
4
8
2
37
9,561
Bottom line: You can’t control when a compromised repository comes back online, but you can control what your workflows run. Pin third-party GitHub Actions to a known-clean commit SHA. That would have stopped this malicious code from running in both May and September.
1
8
827
Compromised MemTensor packages hit npm and PyPI today. Check our analysis for affected versions, cleanup guidance, and updates. socket.dev/blog/memtensor-co…
4
10
2,077
Socket retweeted
Pretty wild how this extension will piece together it's code from a C2 server.
Socket researchers found a malicious Firefox extension that poses as a PDF identity verifier to hijack Google accounts. It fetches its payload after installation, steals Google session cookies, and can silently reset the victim’s password. socket.dev/blog/firefox-goog…
1
4
32
6,995
Socket researchers found a malicious Firefox extension that poses as a PDF identity verifier to hijack Google accounts. It fetches its payload after installation, steals Google session cookies, and can silently reset the victim’s password. socket.dev/blog/firefox-goog…
1
7
2
21
10,376
Compromised MemTensor packages hit npm and PyPI today. Check our analysis for affected versions, cleanup guidance, and updates. socket.dev/blog/memtensor-co…
4
10
2,077
🚨 MemTensor’s npm and PyPI packages have been compromised. Four malicious releases, including the latest version on both registries, drop cross-platform Go binaries that steal npm, PyPI, GitHub, AWS, SSH and other developer secrets. socket.dev/blog/memtensor-co…
6
10
2,637
Lovable rewrote Vite’s dev server in Rust. OJ uses ~75% less memory, and Lovable now provisions sandboxes in 3 seconds instead of 14.5. Evan You thinks AI may make these tailored rewrites more common to where everyone "maintains their own slop fork.” socket.dev/blog/oj-vite-rust
5
14
2,748
Lovable rewrote Vite’s dev server in Rust. OJ uses ~75% less memory, and Lovable now provisions sandboxes in 3 seconds instead of 14.5. Evan You thinks AI may make these tailored rewrites more common to where everyone "maintains their own slop fork.” socket.dev/blog/oj-vite-rust
5
14
2,748
Socket retweeted
The wildest part of a recent npm attack: the C2. The malware phoned home over libp2p, the BitTorrent DHT, IPFS, Ethereum smart contracts, and Nostr relays. Every decentralization protocol, as command-and-control: risky.biz/RBNEWSSI140/
4
14
2,260
Replying to @npmjs
Purchase @SocketSecurity and just scan the universe all the time, every time, even before package publish. Don't make me stage.
4
3
40
3,277