Socket

3.2K posts

Socket banner
Socket

Socket

@SocketSecurity

Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. 👀 @npm_malware

https://socket.dev/careers Katılım Kasım 2021
4.6K Takip Edilen21.6K Takipçiler
Sabitlenmiş Tweet
Socket
Socket@SocketSecurity·
Today is a big day for Socket. x.com/feross/status/…
Feross@feross

Today is a big day for @SocketSecurity. We just raised a $60M Series C at a $1B valuation, led by @ThriveCapital with participation from @a16z, @AbstractVC, and @CapitalOne Ventures. Total funding is now $125M. Four years ago, we started Socket because open source dependencies were flowing into production faster than anyone could vet them. AI has massively accelerated that. Code is being written, shipped, and deployed before any human reads it. Security has to operate at that same speed. One data point from Thrive's diligence that I keep coming back to: they first discovered Socket because @cursor_ai, @OpenAI, and @AnthropicAI all independently told them it was the most important security tool they'd adopted for AI-driven development. Three of the most sophisticated AI companies converging on the same vendor unprompted. Since our Series B, Socket has grown to more than 20,000 organizations, protecting over 1.5 million repositories and blocking more than 1,000 supply chain attacks every week. The team is now over 100 people. Three out of five FAANG companies are Socket customers. So are the companies building the most ambitious AI products: @AnthropicAI, @cursor_ai, @xai, @figma, @vercel, @Replit, @scale_AI, @GustoHQ, @Mercadolibre, and @cribl_io, alongside Fortune 100s in financial services and global media. What we've shipped since the last round: • Socket Firewall blocks malicious packages at install time, before they reach a developer's laptop or CI pipeline. Free for everyone. • Reachability analysis via our acquisition of Coana, eliminating 50-80% of irrelevant vulnerability alerts by focusing only on CVEs that are actually exploitable. • Socket Certified Patches for remediating exploitable CVEs in seconds without waiting on upstream maintainers. • Coverage extending to browser extensions, editor extensions, MCP servers, and AI tools via our acquisition of @secureannex. When the Axios compromise hit, our detection systems flagged the malicious dependency within six minutes. Within 24 hours, more than 2,000 organizations onboarded to Socket to block it. Where the funding goes: deeper investment in Firewall, massively expanding Certified Patches, moving protection closer to every point of install across the developer toolchain, and new product launches pushing Socket into a category we haven't entered before. We're hiring across engineering, sales, customer success, and threat intel. ❤️ Thank you to our customers, investors, and the open-source community for your support. Together, we’re making software safer for everyone.

English
4
3
94
24.9K
Socket
Socket@SocketSecurity·
@ajrgd @feross Great question! GitHub App installation permissions are still managed in GitHub. This release controls access inside Socket: admins can use Custom Roles + Repository Access Permissions to limit which repos a member can see and act on in Socket.
English
0
0
3
21
Socket
Socket@SocketSecurity·
🚀 Socket Launch Week Day 5: Introducing Repository Access Permissions and Custom Roles. Custom Roles set what a user can do. Repository Access Permissions set which repos those actions apply to. Apply least-privilege access without forcing members into broad built-in roles.
Socket tweet media
English
3
5
10
2.3K
Socket
Socket@SocketSecurity·
⭐️ Highlights: - Build custom roles from a base role or from scratch - Scope members to selected repos or all repos - See inherited vs. added permissions separately - Audit every access change ⚡️Available now to all org admins: socket.dev/blog/introduci…
Socket tweet media
English
0
0
3
1.1K
Socket
Socket@SocketSecurity·
🚀 Socket Launch Week Day 4: Socket MCP is getting a massive update! You can now review org alerts, inspect package artifacts, investigate suspicious packages, and use the Socket threat feed directly from your AI assistant.
English
1
6
17
7.9K
Socket retweetledi
tuckner
tuckner@tuckner·
So excited to bring new features to the Socket MCP! Not only can you pull your alerts but you can investigate them deeply at a package level to really understand how they impact your organization!
Socket@SocketSecurity

🚀 Socket Launch Week Day 4: Socket MCP is getting a massive update! You can now review org alerts, inspect package artifacts, investigate suspicious packages, and use the Socket threat feed directly from your AI assistant.

English
1
7
14
4.2K
Socket
Socket@SocketSecurity·
Security teams can ask follow-up questions across alerts, package contents, threat intelligence, and determine org exposure in one place, without clicking through dashboards, registries, and local tooling. ⚡️ Try Socket MCP → socket.dev/blog/socket-mc…
Socket tweet media
English
0
1
7
1.7K
Socket
Socket@SocketSecurity·
New Socket research: We’re seeing more packages designed to trip up AI malware scanners. This new npm package uses prompt-injection-style comments, safety-triggering content, context flooding, and obfuscated JS to probe where scanners refuse, truncate, or miss the code that matters. socket.dev/blog/npm-packa…
Socket tweet media
English
5
24
117
17.4K
Socket
Socket@SocketSecurity·
Available in beta for Enterprise customers: → Blocks malicious installs and updates → Covers VS Code Marketplace and Open VSX → Checks both marketplace results and VSIX downloads → No agent or endpoint software required ⚡️ Learn more: socket.dev/blog/socket-fi…
English
0
1
5
1.3K
Socket
Socket@SocketSecurity·
🚀 Launch Week Day 3: Socket Firewall now blocks malicious code editor extensions. VS Code and Open VSX extensions run inside developer environments with access to source code, terminals, credentials, and tokens. Now teams can block bad extensions before install or update.
GIF
English
2
9
36
10.4K
Socket retweetledi
Sam Bhagwat
Sam Bhagwat@calcsam·
Yesterday, Mastra was hit by a supply chain attack. A malicious postinstall script that exfiltrated credentials and then self-deleted was added to specific versions of our npm packages. Most importantly: the incident is over. All relevant package versions are unpublished. The root cause is that one of our maintainers was compromised. Between 6:12 PM and 6:37PM PT yesterday, a token associated with their account published 116 malicious NPM packages, almost all in the `@mastra/` namespace. We became aware of this at 8:45pm PT. We immediately contacted npm as well as trusted third parties (eg @SocketSecurity). We also began unpublishing, and unpublished 59 packages. As part of the attack, we lost access to some packages. Around 10:15pm PT, we were able to re-add our accounts to those packages. We began unpublishing the rest. In total, we unpublished 110 packages, and deprecated 6. By 11:57pm PT, all affected packages were unpublished or deprecated. At around 1am PT, we also published new, safe versions of each package affected (github.com/mastra-ai/mast…), so that installs would resolve We have always required MFA on NPM for maintainers, but we also allowed (mistakenly) token bypass. Also around 1am PT, we removed token bypass across all packages. At 2:25am PT, we established contact with the compromised maintainer. He is a current, active Mastra employee. His machine was compromised via a social phishing attack. A compromised LinkedIn account reached out to him as well as maintainers of other prominent TypeScript open source packages. He was on a call and clicked a suspicious link. This was the same attack vector as other open-source maintainers have reported (eg x.com/aidenybai/stat…). Around 4:40am, npm responded to the security ticket we'd filed and confirmed the breach. They unpublished the last 6 affected packages. For a third-party report on the incident / malware, including a list of package versions affected, and the mechanisms of the RAT: socket.dev/blog/mastra-np…. We're continuing to keep reducing scope of sensitive credentials and enhance our use of MFA. Security is an ongoing process of review and hardening. Thanks for the hugops. Stay safe out there. I'll be here answering questions.
Sam Bhagwat@calcsam

We have remediated the incident. Brief account on Github: github.com/mastra-ai/mast…

English
9
19
125
21.3K
Socket
Socket@SocketSecurity·
Update: We added our technical analysis for the Mastra npm supply chain attack. The second-stage protocal.cjs implant beacons to C2, supports remote tasking, inventories 166 #crypto wallet browser extensions, collects Chrome/Edge/Brave history, and persists via Windows Run keys, macOS LaunchAgents, and Linux systemd user units. socket.dev/blog/mastra-np…
English
0
6
23
3.1K
Socket retweetledi
Socket
Socket@SocketSecurity·
🚨 More than 140 Mastra npm packages were compromised in a supply chain attack published under the @​mastra/* namespace, including @​mastra/core, which receives more than 918K weekly npm downloads. The attack used easy-day-js, a typosquatted dependency, to deliver a cross-platform infostealer during npm install.
Socket tweet media
English
4
26
61
10.6K
Socket
Socket@SocketSecurity·
This is a developing story. Socket flagged the malicious dependency within six minutes of publication, and Socket users were protected automatically. We’re continuing to analyze the malware and will publish a full technical analysis. socket.dev/blog/mastra-np…
English
1
3
6
2.5K
Socket retweetledi
Socket
Socket@SocketSecurity·
@JFrogSecurity We are getting no breaks. We’re taking incident response from the bar now. 😅 What’s your order? 👀🍸
English
1
0
2
93
JFrog Security
JFrog Security@JFrogSecurity·
@SocketSecurity Look, we can debate supply chain security and malicious packages forever, but the second we get an actual break from these supply chain attacks, walking straight into a bar is not a bad idea. 🐸🍻
English
1
0
6
154