Socket

3.1K posts

Socket banner
Socket

Socket

@SocketSecurity

Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. 👀 @npm_malware

https://socket.dev/careers เข้าร่วม Kasım 2021
4.6K กำลังติดตาม21.5K ผู้ติดตาม
ทวีตที่ปักหมุด
Socket
Socket@SocketSecurity·
Today is a big day for Socket. x.com/feross/status/…
Feross@feross

Today is a big day for @SocketSecurity. We just raised a $60M Series C at a $1B valuation, led by @ThriveCapital with participation from @a16z, @AbstractVC, and @CapitalOne Ventures. Total funding is now $125M. Four years ago, we started Socket because open source dependencies were flowing into production faster than anyone could vet them. AI has massively accelerated that. Code is being written, shipped, and deployed before any human reads it. Security has to operate at that same speed. One data point from Thrive's diligence that I keep coming back to: they first discovered Socket because @cursor_ai, @OpenAI, and @AnthropicAI all independently told them it was the most important security tool they'd adopted for AI-driven development. Three of the most sophisticated AI companies converging on the same vendor unprompted. Since our Series B, Socket has grown to more than 20,000 organizations, protecting over 1.5 million repositories and blocking more than 1,000 supply chain attacks every week. The team is now over 100 people. Three out of five FAANG companies are Socket customers. So are the companies building the most ambitious AI products: @AnthropicAI, @cursor_ai, @xai, @figma, @vercel, @Replit, @scale_AI, @GustoHQ, @Mercadolibre, and @cribl_io, alongside Fortune 100s in financial services and global media. What we've shipped since the last round: • Socket Firewall blocks malicious packages at install time, before they reach a developer's laptop or CI pipeline. Free for everyone. • Reachability analysis via our acquisition of Coana, eliminating 50-80% of irrelevant vulnerability alerts by focusing only on CVEs that are actually exploitable. • Socket Certified Patches for remediating exploitable CVEs in seconds without waiting on upstream maintainers. • Coverage extending to browser extensions, editor extensions, MCP servers, and AI tools via our acquisition of @secureannex. When the Axios compromise hit, our detection systems flagged the malicious dependency within six minutes. Within 24 hours, more than 2,000 organizations onboarded to Socket to block it. Where the funding goes: deeper investment in Firewall, massively expanding Certified Patches, moving protection closer to every point of install across the developer toolchain, and new product launches pushing Socket into a category we haven't entered before. We're hiring across engineering, sales, customer success, and threat intel. ❤️ Thank you to our customers, investors, and the open-source community for your support. Together, we’re making software safer for everyone.

English
4
3
92
24K
Socket
Socket@SocketSecurity·
The US government forced Anthropic to pull Claude Fable on Friday night, days after launch. Users spent the week one-shotting code reviews and migrations. Some upgraded specifically for Fable. Now they’re demanding refunds. Government intervention can now reach directly into a commercial AI product and pull it from the market. socket.dev/blog/us-govern…
English
3
8
47
3.3K
Socket รีทวีตแล้ว
Feross
Feross@feross·
. @AndrewBecherer is joining @SocketSecurity as our first Chief Information Security Officer. Andrew was @datadoghq's first security hire and led its security program through hypergrowth and IPO. He went on to serve as CISO at @Iterable, founded @StarisHQ to work on security for production AI systems, and most recently was CISO at Sublime Security. He started his career at @iSECPartners working on infrastructure security with hyperscalers. Hiring our first CISO was always going to be one of the highest-stakes decisions we make. Socket protects more than 27,000 organizations, including enterprises that depend on us to secure the supply chain behind their most important products. The standard we hold ourselves to has to match the standard we help our customers enforce. Andrew understands the supply chain problem from both sides. He's a defender who's lived through it, and a builder who knows what tools actually help. The environment he's stepping into: AI now writes as much as 90% of code at top engineering organizations. Package hijackings and maintainer compromises that were once a handful of incidents a year now happen weekly. In Andrew's words: "Every CISO I talk to is trying to figure out how to give their developers the open source ecosystem and the AI tooling they need without inheriting somebody else's malicious package. That's the problem Socket exists to solve." Welcome, Andrew. Full post: socket.dev/blog/andrew-be…
English
3
1
23
2.7K
Socket
Socket@SocketSecurity·
@markodayan Glad to help! Looks like you dodged a bullet! 😅
English
0
0
5
543
Mark Odayan
Mark Odayan@markodayan·
Received a suspicious coding assessment for a crypto company I had zero mutual followers with (yet they had 100K+ followers on twitter), I just checked the package.json and found this dependency lol (thank you @SocketSecurity)
Mark Odayan tweet mediaMark Odayan tweet media
English
3
5
36
7.5K
Socket รีทวีตแล้ว
SC Media
SC Media@SCMagazine·
A new Mini Shai-Hulud “Hades” variant has infected 23 PyPI package versions, targeting developers with malware designed to steal tokens, keys and cloud credentials, according to @SocketSecurity. #cybersecurity #CISO #infosec bit.ly/3QxsqEQ
English
1
2
7
1.3K
Socket
Socket@SocketSecurity·
🧩 New Research: 152 Chrome "live wallpaper" extensions hid ad tracking behind false privacy disclosures and faked Google search traffic to support ad monetization. The network spanned 38 publisher accounts, 3 backend brands, and ~105K installs. socket.dev/blog/152-chrom…
English
0
5
16
1.5K
Socket
Socket@SocketSecurity·
Big news for Socket: @andrewbecherer is joining as our first CISO. He brings deep experience leading security at high-growth SaaS companies, and will strengthen the security program behind the infrastructure we operate and the OSS ecosystem we protect. socket.dev/blog/andrew-be…
English
0
3
23
2.1K
Socket รีทวีตแล้ว
John Scott-Railton
John Scott-Railton@jsrailton·
NEW: malware developers added nuclear & biological weapons text to to their spyware. Goal? To trigger LLM safety refusals... so that their spyware wouldn't be analyzed by an AI security scanner. Cleanest practical example I can think of for why over-indexing on first order safety alignment is risky. When closed (and open) models ship with aggressive refusals, they will be sprinkled with second-order blindspots that attackers will discover...and exploit. We are only in the earliest days of attackers leveraging these features, and it wouldn't surprise me if users systems that need to handle complex cybersecurity issues demand that models be less safety-blunted. In the weeds: @SocketSecurity's post also shows why intention matters in how you design a malware analysis pipeline to avoid prompt manipulation. H/T to colleagues that shared this with me socket.dev/blog/mini-shai…
John Scott-Railton tweet media
English
223
2.1K
12.6K
1.5M
Socket รีทวีตแล้ว
Askraa.ai
Askraa.ai@askraaai·
A notable update for @Replit users: @SocketSecurity Firewall is now integrated directly into the development experience and is already stopping more than 8,000 malicious packages every day before they can be installed. #Replit #CyberSecurity #Askraa
Socket@SocketSecurity

🔥 Socket Firewall is now built into @Replit's AI-powered development experience. It’s already blocking 8K malicious packages/day across builders on the platform, giving Replit users stronger protection by default the moment dependencies are introduced. socket.dev/blog/socket-pa…

English
1
1
6
2.4K
Socket รีทวีตแล้ว
Scott Kennedy ⠕
Scott Kennedy ⠕@stkenned·
Worried about malware, CVEs, slopsquatting, and more? Not on Replit! Thanks to our partnership with @SocketSecurity all Replit builders get the same types of protection that we use internally for our engineering team.
Replit ⠕@Replit

Most people run a security scan for malicious packages before publishing a project But the risk starts the moment they're installed Today we're launching Package Firewall, built in partnership with Socket It blocks malware before it ever reaches your app

English
0
3
22
4.5K
Socket รีทวีตแล้ว
Socket รีทวีตแล้ว
Ahmad Nassri
Ahmad Nassri@AhmadNassri·
thrilled to finally announce something I've been working on for a while: @SocketSecurity is officially powering @Replit’s new Package Firewall! By evaluating dependencies directly at the install path, we are protecting builders from hallucinated or malicious packages before they can execute. We're currently blocking 8,000+ bad packages a day across builders on Replit. Ship fast, vibe safely. 🛡️ Read the full breakdown: socket.dev/blog/socket-pa…
English
5
12
48
6.3K
Socket รีทวีตแล้ว
Amjad Masad
Amjad Masad@amasad·
Supply chain attacks — when hackers takeover public packages and then you or your agent install them — have been devastating on the industry, and will become a bigger problem in the future. Proud to say Replit has shielded our customers from every one of these attacks thanks to our partnership with @SocketSecurity
Replit ⠕@Replit

Most people run a security scan for malicious packages before publishing a project But the risk starts the moment they're installed Today we're launching Package Firewall, built in partnership with Socket It blocks malware before it ever reaches your app

English
24
13
174
14.6K
Socket
Socket@SocketSecurity·
🔥 Socket Firewall is now built into @Replit's AI-powered development experience. It’s already blocking 8K malicious packages/day across builders on the platform, giving Replit users stronger protection by default the moment dependencies are introduced. socket.dev/blog/socket-pa…
Socket tweet media
English
1
8
50
9.1K
Socket
Socket@SocketSecurity·
npm accidentally marked a bunch of one-character packages as security holders, including c, i, n, x, several numbers, and even the - package. The registry confirmed it was a tooling bug and said a rollback is underway. socket.dev/blog/npm-tooli…
English
1
8
26
4.4K
Socket รีทวีตแล้ว
Socket
Socket@SocketSecurity·
@M_Schiellerup Makes sense, or just add the repos to your company's Socket account so you can see it in the dashboard. :)
English
1
0
1
44
Mads Schiellerup
Mads Schiellerup@M_Schiellerup·
@SocketSecurity I have made a GitHub organisation scannings tool because my company has a tons of repositories. And instead of checking each, I can give it an advisory or the path to your downloaded file. This way I can check it quicker to see if we are exposed to an attack.
English
1
0
2
61
Socket
Socket@SocketSecurity·
Mini Shai-Hulud/Miasma/Hades are now targeting bioinformatics and MCP developers in a newer PyPI wave. Socket found 23 newly compromised PyPI package-version artifacts using multiple execution paths: → native .abi3.so extensions that run the JavaScript stealer at import time → .pth startup loaders that bootstrap Bun → a new loader variant that searches sys.path for _index.js instead of bundling it in the same wheel The payload also includes a fake prompt-injection header at the top of _index.js to interfere with LLM-based malware triage before scanners reach the obfuscated code.
Socket tweet media
English
10
37
145
18.4K
Socket
Socket@SocketSecurity·
@M_Schiellerup It's available on the campaign page. Sometimes we embed that page directly in the post when we first start a campaign. On a follow-up we usually just link to it. For the most recent one, it's here and you can grab the CSV: socket.dev/supply-chain-a…
English
0
1
18
3.5K
Mads Schiellerup
Mads Schiellerup@M_Schiellerup·
@SocketSecurity For some of your compromised posts, you have this downloadable csv file + lists of packages, and on some posts you only have the list - whats the requirement for this downloadable to be present?
English
2
0
8
5.1K