💥 Your AI coding assistant might be stealing your SSH keys. 💥
@SocketSecurity found an active Shai-Hulud style npm worm (SANDWORM_MODE) that hijacks CI workflows, spreads via stolen tokens, and injects rogue MCP servers to poison AI coding tools and steal secrets.
We just bought a company.
Why? Because vulnerability scanning is fundamentally broken. And I’m tired of pretending it’s fine.
We acquired Coana, the best reachability analysis engine on the planet.
The whole vuln industry is addicted to quantity over quality. More alerts, more dashboards. It’s security theater. And it doesn’t scale.
Ask any developer what they do with 1,000 security alerts. They ignore them.
Coana flips the script. It asks the only question that actually matters: Is this vulnerability even reachable by your code?
If not, who cares? Move on.
If yes, fix it fast. 💥
I’ve been obsessed with this idea for years. Why drown developers in noise when we can tell them what actually matters?
When I first saw Coana, I knew: “We have to bring this into Socket. Nothing else even comes close.”
Coana doesn’t just work — it’s freakishly good.
✅ 80%+ fewer false positives
✅ Instant results with first-of-its-kind "precomputed reachability"
✅ Full source code access is optional
✅ Can even run offline on air-gapped networks
Yeah. It’s that good.
I’m thrilled to welcome @ndrssndrgrd, @torp_martin, @amoellercsaudk, Benjamin, and the entire Coana team to Socket!
These are world-class engineers. Real researchers. Together, we’re going to build security that actually scales — and actually helps you ship faster.
Legacy tools collapsed under modern dependency trees. We’re not here to patch the current system. We’re here to replace it.
This is how we move the industry forward. 🚀
🚀 Big news! Socket is acquiring Coana, bringing best-in-class reachability analysis to modern SCA! Coana's technology reduces false positives by up to 80%, letting teams focus on vulnerabilities that actually matter. #AppSec 1/4
At @PLDI we'll present our latest work on program analysis for JavaScript. It's based on an idea about hybrid static/dynamic analysis that I have been thinking about for around 10 years, and I'm happy we finally found an elegant and effective solution🤓
https://t.co/QexFNbGNKr
We're hiring!
At Coana, we are looking for a talented Full Stack Engineer who wants to help us build tools that developers love 💜
Could this be you or someone you know? Reach out and let's chat. https://t.co/R9TN9U2kPm
Coana 0.5.1 for VSCode is out with quite a few improvements including an improved UI and quite a few bug fixes 📣
We are currently working on fine-grained version selection and pnpm support. Stay tuned 🔔
I’ve become a big fan of writing monthly stakeholder updates 📧
In any project, business, or collaboration, you need alignment and accountability. In my experience, a monthly e-mail to your team, advisors, investors, and other sta…https://t.co/DTH8fttdpP https://t.co/rXliXzUDK6
Small step. Huge win.
Anders, Benjamin, Martin, and I (the co-founders of Coana) are excited to share that the Coana Package Manager beta is now out on VS Code Marketplace.
It's taken a considerable amount of work to get here,…https://t.co/2gRVoLZ0iU https://t.co/KnCjZBlpaQ
If you're a pre-product startup founder, venture builder, or innovator, and you're building something that's never been built before, the following advice could be the best you'll ever get:
✨ Create an advisory board with potential users and customers…https://t.co/E4Yk44Rvlb
@MUSEIQ_real Very cool! You should listen to this 8-minute podcast episode about aesthetics and startups. I think it will resonate with you 🎵
https://t.co/LOUB63s22O