Socket is the #1 software supply chain security platform. Next-gen SCA SBOM 0-day prevention. LOVED BY DEVELOPERS. 👀 @npm_malware

Joined November 2021
238 Photos and videos
Pinned Tweet
Today is a big day for Socket. x.com/feross/status/20571192…

May 20
Today is a big day for @SocketSecurity. We just raised a $60M Series C at a $1B valuation, led by @ThriveCapital with participation from @a16z, @AbstractVC, and @CapitalOne Ventures. Total funding is now $125M. Four years ago, we started Socket because open source dependencies were flowing into production faster than anyone could vet them. AI has massively accelerated that. Code is being written, shipped, and deployed before any human reads it. Security has to operate at that same speed. One data point from Thrive's diligence that I keep coming back to: they first discovered Socket because @cursor_ai, @OpenAI, and @AnthropicAI all independently told them it was the most important security tool they'd adopted for AI-driven development. Three of the most sophisticated AI companies converging on the same vendor unprompted. Since our Series B, Socket has grown to more than 20,000 organizations, protecting over 1.5 million repositories and blocking more than 1,000 supply chain attacks every week. The team is now over 100 people. Three out of five FAANG companies are Socket customers. So are the companies building the most ambitious AI products: @AnthropicAI, @cursor_ai, @xai, @figma, @vercel, @Replit, @scale_AI, @GustoHQ, @Mercadolibre, and @cribl_io, alongside Fortune 100s in financial services and global media. What we've shipped since the last round: • Socket Firewall blocks malicious packages at install time, before they reach a developer's laptop or CI pipeline. Free for everyone. • Reachability analysis via our acquisition of Coana, eliminating 50-80% of irrelevant vulnerability alerts by focusing only on CVEs that are actually exploitable. • Socket Certified Patches for remediating exploitable CVEs in seconds without waiting on upstream maintainers. • Coverage extending to browser extensions, editor extensions, MCP servers, and AI tools via our acquisition of @secureannex. When the Axios compromise hit, our detection systems flagged the malicious dependency within six minutes. Within 24 hours, more than 2,000 organizations onboarded to Socket to block it. Where the funding goes: deeper investment in Firewall, massively expanding Certified Patches, moving protection closer to every point of install across the developer toolchain, and new product launches pushing Socket into a category we haven't entered before. We're hiring across engineering, sales, customer success, and threat intel. ❤️ Thank you to our customers, investors, and the open-source community for your support. Together, we’re making software safer for everyone.
4
3
92
24,136
Socket retweeted
🧩 New Research: 152 Chrome "live wallpaper" extensions hid ad tracking behind false privacy disclosures and faked Google search traffic to support ad monetization. The network spanned 38 publisher accounts, 3 backend brands, and ~105K installs. socket.dev/blog/152-chrome-l…
1
7
26
2,307
Socket retweeted
The US government forced Anthropic to pull Claude Fable on Friday night, days after launch. Users spent the week one-shotting code reviews and migrations. Some upgraded specifically for Fable. Now they’re demanding refunds. Government intervention can now reach directly into a commercial AI product and pull it from the market. socket.dev/blog/us-governmen…
4
15
103
23,975
Socket retweeted
Jun 11
. @AndrewBecherer is joining @SocketSecurity as our first Chief Information Security Officer. Andrew was @datadoghq's first security hire and led its security program through hypergrowth and IPO. He went on to serve as CISO at @Iterable, founded @StarisHQ to work on security for production AI systems, and most recently was CISO at Sublime Security. He started his career at @iSECPartners working on infrastructure security with hyperscalers. Hiring our first CISO was always going to be one of the highest-stakes decisions we make. Socket protects more than 27,000 organizations, including enterprises that depend on us to secure the supply chain behind their most important products. The standard we hold ourselves to has to match the standard we help our customers enforce. Andrew understands the supply chain problem from both sides. He's a defender who's lived through it, and a builder who knows what tools actually help. The environment he's stepping into: AI now writes as much as 90% of code at top engineering organizations. Package hijackings and maintainer compromises that were once a handful of incidents a year now happen weekly. In Andrew's words: "Every CISO I talk to is trying to figure out how to give their developers the open source ecosystem and the AI tooling they need without inheriting somebody else's malicious package. That's the problem Socket exists to solve." Welcome, Andrew. Full post: socket.dev/blog/andrew-beche…
3
1
25
2,989
‼️ Treat coding assessments like untrusted code. Fake hiring pipelines are now a malware delivery channel.
Received a suspicious coding assessment for a crypto company I had zero mutual followers with (yet they had 100K followers on twitter), I just checked the package.json and found this dependency lol (thank you @SocketSecurity)
2
13
74
7,134
Socket retweeted
A new Mini Shai-Hulud “Hades” variant has infected 23 PyPI package versions, targeting developers with malware designed to steal tokens, keys and cloud credentials, according to @SocketSecurity. #cybersecurity #CISO #infosec bit.ly/3QxsqEQ
1
4
9
2,045
Big news for Socket: @andrewbecherer is joining as our first CISO. He brings deep experience leading security at high-growth SaaS companies, and will strengthen the security program behind the infrastructure we operate and the OSS ecosystem we protect. socket.dev/blog/andrew-beche…
3
23
2,132
Socket retweeted
NEW: malware developers added nuclear & biological weapons text to to their spyware. Goal? To trigger LLM safety refusals... so that their spyware wouldn't be analyzed by an AI security scanner. Cleanest practical example I can think of for why over-indexing on first order safety alignment is risky. When closed (and open) models ship with aggressive refusals, they will be sprinkled with second-order blindspots that attackers will discover...and exploit. We are only in the earliest days of attackers leveraging these features, and it wouldn't surprise me if users systems that need to handle complex cybersecurity issues demand that models be less safety-blunted. In the weeds: @SocketSecurity's post also shows why intention matters in how you design a malware analysis pipeline to avoid prompt manipulation. H/T to colleagues that shared this with me socket.dev/blog/mini-shai-hu…
226
2,150
12,624
1,539,684
Socket retweeted
A notable update for @Replit users: @SocketSecurity Firewall is now integrated directly into the development experience and is already stopping more than 8,000 malicious packages every day before they can be installed. #Replit #CyberSecurity #Askraa
🔥 Socket Firewall is now built into @Replit's AI-powered development experience. It’s already blocking 8K malicious packages/day across builders on the platform, giving Replit users stronger protection by default the moment dependencies are introduced. socket.dev/blog/socket-partn…
1
1
6
2,465
Socket retweeted
Worried about malware, CVEs, slopsquatting, and more? Not on Replit! Thanks to our partnership with @SocketSecurity all Replit builders get the same types of protection that we use internally for our engineering team.
Most people run a security scan for malicious packages before publishing a project But the risk starts the moment they're installed Today we're launching Package Firewall, built in partnership with Socket It blocks malware before it ever reaches your app
3
22
4,614
Socket retweeted
Fascinating and clever.
NEW: malware developers added nuclear & biological weapons text to to their spyware. Goal? To trigger LLM safety refusals... so that their spyware wouldn't be analyzed by an AI security scanner. Cleanest practical example I can think of for why over-indexing on first order safety alignment is risky. When closed (and open) models ship with aggressive refusals, they will be sprinkled with second-order blindspots that attackers will discover...and exploit. We are only in the earliest days of attackers leveraging these features, and it wouldn't surprise me if users systems that need to handle complex cybersecurity issues demand that models be less safety-blunted. In the weeds: @SocketSecurity's post also shows why intention matters in how you design a malware analysis pipeline to avoid prompt manipulation. H/T to colleagues that shared this with me socket.dev/blog/mini-shai-hu…
16
30
832
175,262
Socket retweeted
thrilled to finally announce something I've been working on for a while: @SocketSecurity is officially powering @Replit’s new Package Firewall! By evaluating dependencies directly at the install path, we are protecting builders from hallucinated or malicious packages before they can execute. We're currently blocking 8,000 bad packages a day across builders on Replit. Ship fast, vibe safely. 🛡️ Read the full breakdown: socket.dev/blog/socket-partn…
5
12
46
6,302
Socket retweeted
Supply chain attacks — when hackers takeover public packages and then you or your agent install them — have been devastating on the industry, and will become a bigger problem in the future. Proud to say Replit has shielded our customers from every one of these attacks thanks to our partnership with @SocketSecurity
Most people run a security scan for malicious packages before publishing a project But the risk starts the moment they're installed Today we're launching Package Firewall, built in partnership with Socket It blocks malware before it ever reaches your app
24
14
178
14,824
🔥 Socket Firewall is now built into @Replit's AI-powered development experience. It’s already blocking 8K malicious packages/day across builders on the platform, giving Replit users stronger protection by default the moment dependencies are introduced. socket.dev/blog/socket-partn…
1
8
50
9,265
npm accidentally marked a bunch of one-character packages as security holders, including c, i, n, x, several numbers, and even the - package. The registry confirmed it was a tooling bug and said a rollback is underway. socket.dev/blog/npm-tooling-…
1
8
26
4,454
Socket retweeted
This week in "Supply-chain attack weekly"
Mini Shai-Hulud/Miasma/Hades are now targeting bioinformatics and MCP developers in a newer PyPI wave. Socket found 23 newly compromised PyPI package-version artifacts using multiple execution paths: → native .abi3.so extensions that run the JavaScript stealer at import time → .pth startup loaders that bootstrap Bun → a new loader variant that searches sys.path for _index.js instead of bundling it in the same wheel The payload also includes a fake prompt-injection header at the top of _index.js to interfere with LLM-based malware triage before scanners reach the obfuscated code.
1
4
8
3,567
Socket retweeted
Jun 8
new shai hulud wave. interestingly it has this inside the payload to trigger safety refusals in potential defensive scans.
Replying to @SocketSecurity
We are now tracking 471 affected artifacts across npm and PyPI in the Mini Shai-Hulud/Miasma/Hades campaign. The newer PyPI artifacts from this wave have been added to the dedicated campaign tracker. Full breakdown: socket.dev/blog/mini-shai-hu…
15
64
424
121,597
Mini Shai-Hulud/Miasma/Hades are now targeting bioinformatics and MCP developers in a newer PyPI wave. Socket found 23 newly compromised PyPI package-version artifacts using multiple execution paths: → native .abi3.so extensions that run the JavaScript stealer at import time → .pth startup loaders that bootstrap Bun → a new loader variant that searches sys.path for _index.js instead of bundling it in the same wheel The payload also includes a fake prompt-injection header at the top of _index.js to interfere with LLM-based malware triage before scanners reach the obfuscated code.
10
37
145
18,409
We are now tracking 471 affected artifacts across npm and PyPI in the Mini Shai-Hulud/Miasma/Hades campaign. The newer PyPI artifacts from this wave have been added to the dedicated campaign tracker. Full breakdown: socket.dev/blog/mini-shai-hu…
6
36
216
190,673