
Socket
@SocketSecurity
Followers
4K
Following
1K
Media
105
Statuses
2K
Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. đź‘€ @npm_malware
Joined November 2021
🚀 We’re thrilled to announce Socket’s $40M Series B led by @AbstractVC with participation from @eladgil and @a16z!
12
17
65
RT @SocketSecurity: 🚨 Socket’s Threat Research Team has uncovered 60 npm packages using post-install scripts to silently exfiltrate hostnam….
0
4
0
Microsoft just announced "TypeScript Native Previews." .🎉 The new Go-based compiler is now on npm for public testing, with 10x faster builds and a VS Code extension for early editor support. Here’s what’s new →.#JavaScript #Typescript.
0
2
4
RT @kpandya_7: 🚨 New npm malware campaign targeting:.• React.• Vue.• Vite.• Node.js.• Quill editor. Deletes files. Crashes systems. Breaks….
0
3
0
RT @SocketSecurity: ⛔ Open source maintainers are urging GitHub to let them block Copilot from submitting AI-generated issues and PRs to th….
0
7
0
RT @happygeek: By me @Forbes: Instagram and TikTok accounts targeted by trio of automated credential checking tools. #kudos @SocketSecurity….
0
2
0
RT @TheHackersNews: 👀 Devs, you're being hunted. 3 Python packages quietly turned stolen emails into verified TikTok & Instagram targets.….
0
35
0
🚨 Socket found a malicious npm plugin that backdoors Koishi chatbots, exfiltrating any message containing an 8-character hex string to a QQ account. A clear instance of supply chain threats in #chatbot frameworks:. #JavaScript #cybersecurity.
0
1
3
RT @SocketSecurity: 📦 Not all packages are what they seem. In our 2025 mid-year threat report, we break down the top trends in how attacker….
0
4
0
RT @SocketSecurity: The Node.js TSC has declined to endorse a feature bounty program, citing concerns over incentives, governance, and proj….
0
3
0
🚨 New threat research: Malicious #Python packages are abusing TikTok & Instagram APIs to verify stolen emails, enabling targeted account attacks and dark web credential sales.
0
2
2
🚨 Too many security alerts? We're fixing that. Excited to see @TheRegister cover our acquisition of Coana, an elite team building next-gen reachability analysis to cut through vulnerability noise.
0
2
1
The Node.js TSC has declined to endorse a feature bounty program, citing concerns over incentives, governance, and project neutrality. Full breakdown of the decision on the Socket blog →.#nodejs #javascript.
0
3
3
⚠️ New Node.js security release patches a high-severity bug: async cryptographic operations on untrusted input could crash your server (CVE-2025-23166). If you’re on 20.x, 22.x, 23.x, or 24.x, update now. #nodejs.
The Node.js security release is out! đź’š. We have released new versions of 20, 22, 23, and 24 release lines in order to address: . - 1 high severity issue .- 1 moderate severity issue .- 1 low severity issue .
0
1
1
RT @BrendanEich: @ajrgd For dependency graph aka software supply chain security, options include @SocketSecurity, from @feross and team.
0
12
0
Latest update from CISA on its plan to kill off RSS feeds in favor of publishing updates on X: "We have paused immediate changes while we re-assess the best approach to sharing with our stakeholders."
CISA has quietly killed off its RSS feeds for KEVs and cyber alerts, replacing an open, automation-friendly format with email and social media alerts. A small change with big consequences for threat monitoring tools that relied on RSS: .
1
1
2