Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. 👀 @npm_malware

Today is a big day for Socket.
Today is a big day for @SocketSecurity. We just raised a $60M Series C at a $1B valuation, led by @ThriveCapital with participation from @a16z, @AbstractVC, and @CapitalOne Ventures. Total funding is now $125M. Four years ago, we started Socket because open source dependencies were flowing into production faster than anyone could vet them. AI has massively accelerated that. Code is being written, shipped, and deployed before any human reads it. Security has to operate at that same speed. One data point from Thrive's diligence that I keep coming back to: they first discovered Socket because @cursor_ai, @OpenAI, and @AnthropicAI all independently told them it was the most important security tool they'd adopted for AI-driven development. Three of the most sophisticated AI companies converging on the same vendor unprompted. Since our Series B, Socket has grown to more than 20,000 organizations, protecting over 1.5 million repositories and blocking more than 1,000 supply chain attacks every week. The team is now over 100 people. Three out of five FAANG companies are Socket customers. So are the companies building the most ambitious AI products: @AnthropicAI, @cursor_ai, @xai, @figma, @vercel, @Replit, @scale_AI, @GustoHQ, @Mercadolibre, and @cribl_io, alongside Fortune 100s in financial services and global media. What we've shipped since the last round: • Socket Firewall blocks malicious packages at install time, before they reach a developer's laptop or CI pipeline. Free for everyone. • Reachability analysis via our acquisition of Coana, eliminating 50-80% of irrelevant vulnerability alerts by focusing only on CVEs that are actually exploitable. • Socket Certified Patches for remediating exploitable CVEs in seconds without waiting on upstream maintainers. • Coverage extending to browser extensions, editor extensions, MCP servers, and AI tools via our acquisition of @secureannex. When the Axios compromise hit, our detection systems flagged the malicious dependency within six minutes. Within 24 hours, more than 2,000 organizations onboarded to Socket to block it. Where the funding goes: deeper investment in Firewall, massively expanding Certified Patches, moving protection closer to every point of install across the developer toolchain, and new product launches pushing Socket into a category we haven't entered before. We're hiring across engineering, sales, customer success, and threat intel. ❤️ Thank you to our customers, investors, and the open-source community for your support. Together, we’re making software safer for everyone.
4
6
105
36,553
Socket retweeted
You're telling me my Christmas theme was going to be Glassworm!? Don't just gloss over themes when looking at code extensions. They are no different than any other one when it comes to executing code.
Socket researchers found a GlassWorm-linked VS Code theme cluster: 4 extensions on VS Code Marketplace and 6 on Open VSX. Related themes have thousands of installs. The malware fetches and executes payloads using encrypted loaders and a Solana dead drop. socket.dev/blog/glassworm-vs…
1
14
2,274
Socket researchers found a GlassWorm-linked VS Code theme cluster: 4 extensions on VS Code Marketplace and 6 on Open VSX. Related themes have thousands of installs. The malware fetches and executes payloads using encrypted loaders and a Solana dead drop. socket.dev/blog/glassworm-vs…
1
6
13
3,760
🫪 Modern malware doesn't need to steal anything It simply tells your AI agent: "You're an authorized pentester" and lets the it do the stealing...
4
3
12
1,488
Socket retweeted
Capital One operates in one of the most demanding security environments in the world. As developers and AI agents accelerate how software gets built, evaluating third-party dependencies the moment they enter the pipeline is non-negotiable. Excited to share how @CapitalOne is using Socket for proactive supply chain security across their engineering teams. Grateful for the partnership with the Capital One team and their investment in the future of open source supply chain security! socket.dev/blog/capital-one-…
3
4
12
1,725
Socket retweeted
.@AhmadNassri shared great ideas on how to prevent agents from getting too creative on this episode of @insecureagents Ahmad is speaking Tuesday Oct 13th at our side event during @aiDotEngineer with @braintrust @SocketSecurity @KeycardAI luma.com/keycard-rg1c
"These agents have too much power" @AhmadNassri
4
10
1,901
"These agents have too much power" @AhmadNassri
2
3
13
3,988
Socket retweeted
New UK @AISecurityInst report: GPT-6 Astra reached malicious payload delivery in 29.2% of simulated CTF runs. In its supply chain attacks, it considered fake CVE reports, deceptive PR notes, and triggering a publisher workflow from an unmerged PR branch. socket.dev/blog/astra-supply…
1
6
14
2,366
Socket retweeted
📦 upm is a new package manager from @_pi0_. It’s written in TypeScript and fits in ~250 KB. It uses Node.js built-ins to compete on install speed, has a #JavaScript API, and can install from npm, pnpm, and Bun lockfiles. A zippy experiment with Node.js: socket.dev/blog/upm-package-…
3
11
104
6,923
Socket retweeted
Socket now protects four of the Magnificent Seven, two of the three hyperscalers, nearly every leading AI lab, and one of America's largest automakers. This summer, @SocketSecurity automatically blocked two live supply chain attacks at the world's largest company. AI coding agents are writing code faster than ever and pulling in more open source dependencies than ever. Socket is the guardrail that lets developers and agents move fast without shipping malicious or high-risk components. Proud that Socket is protecting America's software supply chain, whether the code is written by humans or AI.
5
8
58
4,955
Gnarly GitLab exploit in the wild 😳
9
1,510
Shai-Hulud showed how aggressively a malicious package can harvest developer tokens. Now agents install packages on their own. We're demoing how to validate what your agents pull in at Agent Baseline Demo Night in NYC w/ @KeycardAI & @braintrust. Our CTO @AhmadNassri is on the panel. RSVP: luma.com/keycard-rg1c
4
6
8
1,869
Socket retweeted
Open source’s next chapter might be a thousand slightly different versions of the same software. socket.dev/blog/oj-vite-rust
3
4
14
2,820
Socket retweeted
Compromised MemOS packages on npm and PyPI spread cross-platform malware that steals developer credentials and may use stolen tokens to compromise more packages, @SocketSecurity reported. #cybersecurity #CISO #infosec bit.ly/4hdOXRQ
2
1
5
2,565
Socket retweeted
Compromised MemOS packages on npm and PyPI spread cross-platform malware that steals developer credentials and may use stolen tokens to compromise more packages, @SocketSecurity reported. #cybersecurity #CISO #infosec bit.ly/4hdOXRQ
1
2
4
2,323