SocketSecurity Profile Banner
Socket Profile
Socket

@SocketSecurity

Followers
5K
Following
2K
Media
152
Statuses
2K

Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. 👀 @npm_malware

https://socket.dev/careers
Joined November 2021
Don't wanna be here? Send us removal request.
@SocketSecurity
Socket
1 year
🚀 We’re thrilled to announce Socket’s $40M Series B led by @AbstractVC with participation from @eladgil and @a16z!
12
16
75
@feross
Feross
2 days
We're so honored to be working with the incredible security team at JumpCloud!
@SocketSecurity
Socket
2 days
“With Socket we can get ahead of threats and prevent malicious packages from being pulled down at all. That’s a huge gap we can close and sleep better at night.” – Lawrence Elitzer, Director of Security, @JumpCloud
0
1
2
@ljharb
Jordan Harband
4 days
Excited to announce I've joined @SocketSecurity as an Open Source Architect :-)
4
2
37
@SocketSecurity
Socket
2 days
🚨 New from Socket Threat Research: 9 malicious #NuGet packages deliver time-delayed destructive payloads, designed to crash apps and sabotage industrial control systems. Read the full analysis → https://t.co/UAIWAFTvZ1 #dotnet
Tweet card summary image
socket.dev
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control system...
0
4
5
@SocketSecurity
Socket
2 days
Learn how @JumpCloud partnered with Socket to: ⚡ Gain visibility across OSS, licenses & dev environments ⚡ Focus engineers on real, reachable risks ⚡ Block malicious packages with Socket Firewall ⚡ Instantly secure 600+ repos via a simple GitHub App https://t.co/wZkBPuVFXC
Tweet card summary image
socket.dev
JumpCloud improves visibility into open source and developer threats with Socket, reducing noise and closing gaps across dependencies and environments...
0
0
0
@SocketSecurity
Socket
2 days
“With Socket we can get ahead of threats and prevent malicious packages from being pulled down at all. That’s a huge gap we can close and sleep better at night.” – Lawrence Elitzer, Director of Security, @JumpCloud
1
1
4
@SocketSecurity
Socket
3 days
Check out Socket CTO @AhmadNassri at @WorkOS' Enterprise Ready Conf: Ahmad joined a panel discussing how enterprise security is adapting, as AI speeds up both software development and attacks targeting developer machines. https://t.co/s6L531E8Y9
Tweet card summary image
socket.dev
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.
0
2
2
@feross
Feross
7 days
🎃
@SocketSecurity
Socket
8 days
Still installing npm packages like it’s 2020? Not all npm installs are treats. 🎃 On the @changelog podcast, @feross shares practical steps every developer should take to reduce exposure to supply chain attacks on npm. → https://t.co/LolvzNztAI #NodeJS #JavaScript
0
1
3
@SCMagazine
SC Media
5 days
Ten npm packages, using typosquatting to imitate popular legitimate packages, were found to spread credential-stealing malware hidden under four layers of obfuscation, @SocketSecurity reported. #cybersecurity #infosec #ITsecurity #CISO
Tweet card summary image
scworld.com
The 10 typosquatted packages imitate discord.js, TypeScript and other popular packages.
0
1
3
@SCMagazine
SC Media
7 days
Ten npm packages, using typosquatting to imitate popular legitimate packages, were found to spread credential-stealing malware hidden under four layers of obfuscation, @SocketSecurity reported. #cybersecurity #infosec #ITsecurity #CISO
Tweet card summary image
scworld.com
The 10 typosquatted packages imitate discord.js, TypeScript and other popular packages.
0
1
1
@SocketSecurity
Socket
8 days
‼️Update: the MIT-linked “AI-powered ransomware” report appears to have been taken offline. We updated our post to include an Internet Archive link to the original paper.
@SocketSecurity
Socket
9 days
🧯The security community is pushing back against new claims that 80% of #ransomware attacks are AI-driven, a figure from a recent MIT-linked report now drawing widespread criticism. → https://t.co/wVYjRJXEua
0
2
1
@SocketSecurity
Socket
8 days
Still installing npm packages like it’s 2020? Not all npm installs are treats. 🎃 On the @changelog podcast, @feross shares practical steps every developer should take to reduce exposure to supply chain attacks on npm. → https://t.co/LolvzNztAI #NodeJS #JavaScript
0
2
9
@SCMagazine
SC Media
8 days
Ten npm packages, using typosquatting to imitate popular legitimate packages, were found to spread credential-stealing malware hidden under four layers of obfuscation, @SocketSecurity reported. #cybersecurity #infosec #ITsecurity #CISO
Tweet card summary image
scworld.com
The 10 typosquatted packages imitate discord.js, TypeScript and other popular packages.
0
2
4
@SocketSecurity
Socket
9 days
🧯The security community is pushing back against new claims that 80% of #ransomware attacks are AI-driven, a figure from a recent MIT-linked report now drawing widespread criticism. → https://t.co/wVYjRJXEua
Tweet card summary image
socket.dev
Experts push back on new claims about AI-driven ransomware, warning that hype and sponsored research are distorting how the threat is understood.
1
2
7
@feross
Feross
9 days
Excellent work from the @SocketSecurity team!
@SCMagazine
SC Media
9 days
Ten npm packages, using typosquatting to imitate popular legitimate packages, were found to spread credential-stealing malware hidden under four layers of obfuscation, @SocketSecurity reported. #cybersecurity #infosec #ITsecurity #CISO
0
3
10
@SocketSecurity
Socket
9 days
🧯The security community is pushing back against new claims that 80% of #ransomware attacks are AI-driven, a figure from a recent MIT-linked report now drawing widespread criticism. → https://t.co/wVYjRJXEua
Tweet card summary image
socket.dev
Experts push back on new claims about AI-driven ransomware, warning that hype and sponsored research are distorting how the threat is understood.
1
2
7
@TheHackersNews
The Hacker News
10 days
🚨 10 fake npm packages (~9.9K installs) hid a cross-platform info stealer. It spawns a fake terminal, pulls a 24 MB payload from 195.133.79[.]43, and drains keyrings — not just browser creds. Instant access to email, cloud, VPNs, and prod DBs. Read details ↓
2
68
167
@SocketSecurity
Socket
10 days
The #Ruby ecosystem is entering a new phase of governance for its core package tools. Ruby creator Matz assumes control of RubyGems and Bundler as former maintainers agree to transfer all rights to end the dispute. #rubyonrails https://t.co/26iOO5Y0Dh
Tweet card summary image
socket.dev
Ruby's creator Matz assumes control of RubyGems and Bundler repositories while former maintainers agree to step back and transfer all rights to end th...
0
2
5
@SocketSecurity
Socket
11 days
Socket threat researchers found 10 typosquatted npm packages that auto-run via postinstall, display fake CAPTCHAs, fingerprint IPs, and install a cross-platform credential stealer. Together, they’ve been downloaded ~9,900 times. Read the report →
Tweet card summary image
socket.dev
Socket researchers found 10 typosquatted npm packages that auto-run on install, show fake CAPTCHAs, fingerprint by IP, and deploy a credential stealer...
1
3
9
@SocketSecurity
Socket
15 days
🔥 Socket Firewall Enterprise adds: • On-prem deployment for secure environments • Configurable security and license policies • Expanded language and registry support • Telemetry and visibility across developer machines Learn more →
Tweet card summary image
socket.dev
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.
0
0
1
@SocketSecurity
Socket
15 days
🚀 Socket Launch Day 5! Malicious packages are infiltrating development environments before they ever reach production. Today we're answering these threats with the release of Socket Firewall Enterprise: configurable, enterprise-grade protection for modern package ecosystems.
1
2
3