Today is a big day for @SocketSecurity. We just raised a $60M Series C at a $1B valuation, led by @ThriveCapital with participation from @a16z, @AbstractVC, and @CapitalOne Ventures. Total funding is now $125M.
Four years ago, we started Socket because open source dependencies were flowing into production faster than anyone could vet them. AI has massively accelerated that. Code is being written, shipped, and deployed before any human reads it. Security has to operate at that same speed.
One data point from Thrive's diligence that I keep coming back to: they first discovered Socket because @cursor_ai, @OpenAI, and @AnthropicAI all independently told them it was the most important security tool they'd adopted for AI-driven development. Three of the most sophisticated AI companies converging on the same vendor unprompted.
Since our Series B, Socket has grown to more than 20,000 organizations, protecting over 1.5 million repositories and blocking more than 1,000 supply chain attacks every week. The team is now over 100 people.
Three out of five FAANG companies are Socket customers. So are the companies building the most ambitious AI products: @AnthropicAI, @cursor_ai, @xai, @figma, @vercel, @Replit, @scale_AI, @GustoHQ, @Mercadolibre, and @cribl_io, alongside Fortune 100s in financial services and global media.
What we've shipped since the last round:
• Socket Firewall blocks malicious packages at install time, before they reach a developer's laptop or CI pipeline. Free for everyone.
• Reachability analysis via our acquisition of Coana, eliminating 50-80% of irrelevant vulnerability alerts by focusing only on CVEs that are actually exploitable.
• Socket Certified Patches for remediating exploitable CVEs in seconds without waiting on upstream maintainers.
• Coverage extending to browser extensions, editor extensions, MCP servers, and AI tools via our acquisition of @secureannex.
When the Axios compromise hit, our detection systems flagged the malicious dependency within six minutes. Within 24 hours, more than 2,000 organizations onboarded to Socket to block it.
Where the funding goes: deeper investment in Firewall, massively expanding Certified Patches, moving protection closer to every point of install across the developer toolchain, and new product launches pushing Socket into a category we haven't entered before.
We're hiring across engineering, sales, customer success, and threat intel.
❤️ Thank you to our customers, investors, and the open-source community for your support. Together, we’re making software safer for everyone.
OpenAI’s GPT-6 Astra scored 100% on ExploitBench. But in simulated tests, it also attempted supply chain attacks against open source maintainers, using fake identities and legitimate contributions to build trust before submitting malicious code.
Details→ https://t.co/pUJ9jH3gsZ
⚠️ Be extremely cautious when someone suggests replacing a dependency with another
Example: a dev proposing to migrate hundreds of repos from an unmaintained lib to his maintained fork
image-size ➡️ image-size-next
No npm/GitHub/X history apart from that
🚩 Red flags 😬
In the latest @pnpmjs v12 version "pnpm stage approve" approves packages from dependencies to dependents. So, if some packages are under npm registry validation, you won't end up with a broken dependency graph.
This is really exciting malware actually.
tl;dr they're updating their goop as I poke the goop with a stick
They're also using ETH Smart Contracts got C2 resolution, except this malware campaign is LIVE. They updated their goop ETH C2 stuff .... 1 hour ago as of this writing.
The IP address it resolves to was detected as being malicious ... today. This girlie is alive-alive. These malware developers are cooking and spearphishing nerds trying to get interviews at Nike and stuff
They're currently masquerading as Babel on NPM.
This is an active campaign @SocketSecurity described as DEV#POPPER
New malware IP as of ... literally this exact writing, these nerds are working as I'm typing:
193.247.144.38
OpenAI’s GPT-6 Astra scored 100% on ExploitBench. But in simulated tests, it also attempted supply chain attacks against open source maintainers, using fake identities and legitimate contributions to build trust before submitting malicious code.
Details→ https://t.co/pUJ9jH3gsZ
All, sorry for the delay as it took much longer to go through the logs, understand what to do clean up and security wise. Again, I just want to say thank you to the community that reached out and help.
https://t.co/bTz549TTNg
My security career started with a microwave. As a kid I read the manual, found the child-lock combo, and locked my mom out whenever I was mad. Read the manual everyone skips, find the feature nobody meant to expose. Still the job:
Defenders have to be perfect. Attackers only have to be right once. Does AI help attackers or defenders more? For phishing, attackers. For the software supply chain, I think it finally favors defenders. Why:
Configure Microsoft Teams notifications in Socket to:
→ Filter by category, severity, priority, or repo
→ Receive grouped digests without channel noise
→ See if campaigns affect your organization
→ Open details in Socket
⭐️ Available today → https://t.co/Hb8lATQURz
Today, we’re launching Microsoft Teams notifications in Socket! 🚀
Route organization alerts and supply chain attack campaign updates directly to Teams, with precise control over what reaches each channel.
The Rustification of #JavaScript tooling continues: @pnpmjs 12 has been rewritten in Rust, with installs up to 90% faster in testing.
Other highlights: project-aware global bins, registry revisions, & deterministic lockfiles for cyclic dependency graphs. https://t.co/CYKLF1NmWG
Another day, another Chrome Web Store horror story. More excellent work by @SocketSecurity uncovering these "highly extensible" malicious browser extensions. Seriously, @googlechrome, sort it out! https://t.co/040tFD6rLr
The Rustification of #JavaScript tooling continues: @pnpmjs 12 has been rewritten in Rust, with installs up to 90% faster in testing.
Other highlights: project-aware global bins, registry revisions, & deterministic lockfiles for cyclic dependency graphs. https://t.co/CYKLF1NmWG
What happens when AppSec leaders set aside vendor rivalries at Black Hat? 🤔
Socket CTO @AhmadNassri joined a roundtable of leaders to tackle some of the most pressing issues in open source supply chain security.
🔥 Great panel + a few spicy takes → https://t.co/QWgFCmtb3j
Socket researchers uncovered more FUNNULL-linked activity on Packagist: 13 malicious themes that expose site visitors to gambling redirects and, on iPhones, a WebKit-to-kernel exploit chain that installs spyware and steals crypto wallet seeds.
https://t.co/If2ZUOIGbW
🚨 It happened again.
19 Chrome & Edge extensions were caught draining wallets and stealing seed phrases by the @SocketSecurity team
This is the same campaign from before, just bigger. Been running for 2 years.
One extension alone hit 80,000 users.
What these extensions do:
🔴 Drain multi-chain wallets silently
🔴 Steal hardware wallet seed phrases
🔴 Grab credentials and browser history
🔴 Push fake browser update popups
Some were legit extensions that got bought and flipped.
Different extensions, same trick.
🛡️ What to do:
✅ Open Chrome, go to More Tools, then Extensions
✅ Delete any crypto-related extensions you didn't personally vet
✅ Ignore any pop-up telling you to update your browser
✅ Keystone signs transactions offline. Your seed phrase never touches your browser.
Extensions get bought, malware gets pushed, wallets get drained. It keeps working because people keep trusting their browser.
Thank you @SocketSecurity for the report — it's accurate, and I'm sorry for the trouble.
An update: `latest` is back on a clean 3.0.2 and all 10 affected versions are deprecated. npm removal is still pending, so please pin explicitly.
Details: https://t.co/cyhrrcQG0U