Discover what is hiding in your software extensions. Acquired by @SocketSecurity

Joined July 2024
3 Photos and videos
On a mission to secure the developer endpoint as more people become developers 💪
May 20
Today is a big day for @SocketSecurity. We just raised a $60M Series C at a $1B valuation, led by @ThriveCapital with participation from @a16z, @AbstractVC, and @CapitalOne Ventures. Total funding is now $125M. Four years ago, we started Socket because open source dependencies were flowing into production faster than anyone could vet them. AI has massively accelerated that. Code is being written, shipped, and deployed before any human reads it. Security has to operate at that same speed. One data point from Thrive's diligence that I keep coming back to: they first discovered Socket because @cursor_ai, @OpenAI, and @AnthropicAI all independently told them it was the most important security tool they'd adopted for AI-driven development. Three of the most sophisticated AI companies converging on the same vendor unprompted. Since our Series B, Socket has grown to more than 20,000 organizations, protecting over 1.5 million repositories and blocking more than 1,000 supply chain attacks every week. The team is now over 100 people. Three out of five FAANG companies are Socket customers. So are the companies building the most ambitious AI products: @AnthropicAI, @cursor_ai, @xai, @figma, @vercel, @Replit, @scale_AI, @GustoHQ, @Mercadolibre, and @cribl_io, alongside Fortune 100s in financial services and global media. What we've shipped since the last round: • Socket Firewall blocks malicious packages at install time, before they reach a developer's laptop or CI pipeline. Free for everyone. • Reachability analysis via our acquisition of Coana, eliminating 50-80% of irrelevant vulnerability alerts by focusing only on CVEs that are actually exploitable. • Socket Certified Patches for remediating exploitable CVEs in seconds without waiting on upstream maintainers. • Coverage extending to browser extensions, editor extensions, MCP servers, and AI tools via our acquisition of @secureannex. When the Axios compromise hit, our detection systems flagged the malicious dependency within six minutes. Within 24 hours, more than 2,000 organizations onboarded to Socket to block it. Where the funding goes: deeper investment in Firewall, massively expanding Certified Patches, moving protection closer to every point of install across the developer toolchain, and new product launches pushing Socket into a category we haven't entered before. We're hiring across engineering, sales, customer success, and threat intel. ❤️ Thank you to our customers, investors, and the open-source community for your support. Together, we’re making software safer for everyone.
1
3
898
🤯🤯🤯🤯
🚨 BREAKING: Socket is investigating an active npm supply chain attack compromising hundreds of packages in the @antv ecosystem. The malicious publish wave appears tied to Mini Shai-Hulud and packages connected to the npm maintainer account atool.
2
156
Today we're announcing that @secureannex has been acquired by @SocketSecurity! Supply chain security is a deceptively wide problem from open source code to browser extensions. Developers and IT teams can't stop it from impacting their organization alone. secureannex.com/blog/annex-a…
5
375
RT @levelsio: Chrome extensions are so incredibly unsafe Malware criminals find popular ones, pay the owners of the extension lots of mone…
93
12
Annex Security (acq by Socket) retweeted
HEADS UP. Popular JSON formatter extension has started injecting geolocation tracking and donation UI into websites Reddit thread seems to think they are also swapping tracking IDs for affiliates (a-la honey) Uninstall and switch to another one
96
221
1,801
324,949
Annex Security (acq by Socket) retweeted
Replying to @wesbos
"Mom, how did we get so rich?" "Your dad created an open source chrome extension then rug pulled everyone and injected malicious code, sold everyone's data and received affiliate money for every purchase they made online"
2
34
1,376
That extension that looks fine? Attackers use this one simple trick to slip malware into your marchine.
Mar 12
Code extensions can declare an 'extensionPack' in their package.json to install other 'supporting' extensions. I detected a suspicious Python extension published today that installs another extension called my-command-pallete which was published 2 days ago.
1
181
Annex Security (acq by Socket) retweeted
Feb 26
A Chrome extension with 7,000 users and a Google Featured badge was recently sold, weaponized, and pushed a malicious update to that executed code through a hidden pixel. Here's how it worked 👇
5
78
352
37,765
Annex Security (acq by Socket) retweeted
Feb 23
🧨 New CrashFix techniques found in browser extensions. "Pixel Shield" — a fully functional ad blocker (4.7 stars, 561 users) because it is a uBlock Origin clone. Hidden inside: a "Promise Bomb" that creates 10 MILLION unresolvable promises to crash your browser on command.
1
18
94
13,170
Annex Security (acq by Socket) retweeted
Feb 11
This report contains 287 browser extensions tracking 37 million users. These were identified using methodology of sandboxing extensions, automatically browsing to URLs, and measuring a data ratio transferred. Real companies, fake services, well established, it's a mixed bag.
2
36
182
50,108
Annex Security (acq by Socket) retweeted
Jan 28
The next supply chain worm has been seeded in Open VSX. A cloned Angular extension with 5000 downloads has been available for two weeks and was updated with malware 6 days ago. This multi stage attack uses etherhiding, gcal c2, rust implants, and more. annex.security/blog/worms-lu…
2
9
47
10,259
Annex Security (acq by Socket) retweeted
Needless to say. If you aren’t using secureannex.com wyd????

. @tuckner has (rightfully) made me so paranoid about chrome extensions.
1
3
517
Think browser extensions are just PUPs? Here are the real impacts.
Fake browser crash → fake extension → real RAT. KongTuke's “CrashFix” tricks users into installing a malicious Chrome extension. Domain-joined victims hit with ModeloRAT—a Python backdoor with persistence and C2. @RussianPanda9xx @wbmmfq @Curity4201 - okt.to/lXj0zP
2
153
Annex Security (acq by Socket) retweeted
Jan 17
I also used @secureannex and @IceSolst's @CRXaminer when I was analyzing it originally. Both very helpful tools! app.secureannex.com/extensio… crxaminer.tech/scan/cpcdkmjd…
2
14
576
Annex Security (acq by Socket) retweeted
29 Dec 2025
A browser extension with over a million users is poaching the prompts of leading AI chat tools. SimilarWeb loads obfuscated remote configuration to collect the prompts, responses and metadata of your conversations. Your private thoughts are analytics companies gain. secureannex.com/blog/prompt-…
5
21
6,030
Annex Security (acq by Socket) retweeted
We’ve identified a security incident affecting Trust Wallet Browser Extension version 2.68 only. Users with Browser Extension 2.68 should disable and upgrade to 2.69. Please refer to the official Chrome Webstore link here: chrome.google.com/webstore/d… Please note: Mobile-only users and all other browser extension versions are not impacted. We understand how concerning this is and our team is actively working on the issue. We’ll keep sharing updates as soon as possible.
808
872
3,000
2,934,288
Annex Security (acq by Socket) retweeted
Glassworm's resurgence | by @secureannex @tuckner "we've identified and tracked an unprecedented 23 extensions which copy other popular extensions, update after publishing with malware, manipulate download counts, and use KNOWN attack signatures which have been in use for months" secureannex.com/blog/glasswo…
1
6
40
6,205
Annex Security (acq by Socket) retweeted
1 Dec 2025
Glassworm returned in a big way during the holiday. We're tracking 23 code extensions across the VS Marketplace and Open VSX which copy popular extensions, evade filters, manipulate their download counts, and then update with sinister malware. secureannex.com/blog/glasswo…
8
18
2,322