Sign in

Socket

@socket.dev
1.2K followers 382 following 699 posts

Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. socket.dev

PostsRepliesMedia
Socket @socket.dev · 29/09/2026
Gnarly GitLab exploit in the wild 😳
041
Socket @socket.dev · 26/09/2026
Open source’s next chapter might be a thousand slightly different versions of the same software. socket.dev/blog/oj-vite...
162
Socket @socket.dev · 23/09/2026
Compromised MemTensor packages hit npm and PyPI today. Check our analysis for affected versions, cleanup guidance, and updates. socket.dev/blog/memtens...
010
Socket @socket.dev · 01/09/2026
Configure Microsoft Teams notifications in Socket to: → Filter by category, severity, priority, or repo → Receive grouped digests without channel noise → See whether campaigns affect your organization → Open details in Socket ⭐ Available today → socket.dev/blog/microso...
010
Socket @socket.dev · 01/09/2026
Today, we’re launching Microsoft Teams notifications in Socket! 🚀 Route organization alerts and supply chain attack campaign updates directly to Teams, with precise control over what reaches each channel.
261
Socket @socket.dev · 26/08/2026
With Socket for ClickUp, you can now: → Create tasks from individual alerts → Route findings automatically with ticketing rules → Set the List, priority, tags, and assignee → Sync task and alert status both ways Learn more: socket.dev/blog/socket-...
010
Socket @socket.dev · 26/08/2026
🚀 We’re excited to launch Socket for ClickUp, now in beta! Move security findings from discovery to assigned, trackable work in ClickUp, with the context teams need to resolve them.
110
Socket @socket.dev · 25/08/2026
Socket for Asana lets you: → Create tasks from any alert or automatically → Filter rules by type, priority, repo, and more → Choose workspace, project, tags, and assignee → Sync task and alert status changes Now in beta for Business and Enterprise: socket.dev/blog/socket-...
000
Socket @socket.dev · 25/08/2026
🚀 Today we’re excited to launch Socket for Asana. The new integration turns Socket alerts into assigned, trackable Asana tasks and keeps both systems in sync as remediation moves forward.
120
Socket @socket.dev · 22/08/2026
“Before Socket, the traditional SCA and SAST companies were looking at a very narrow appsec space. Socket looks at the supply chain holistically, across firewall, threat intel, and SCA. That lets you combine all of it with your security program and see the benefits fast.” - Mohit Bansal, Webflow
131
Socket @socket.dev · 20/08/2026
A common pattern we've seen: an extension can start clean, then turn malicious in an update. Socket monitors each version to surface that change. Available today for enterprise customers: socket.dev/blog/firefox...
020
Socket @socket.dev · 10/08/2026
"Socket has won the trust of the whole team. One of our defaults now is to ask whether Socket can solve a problem for us. Anything they build, we want to take a look at it." - Travis McPeak, Security Lead, Cursor
1120
Socket @socket.dev · 04/08/2026
🚨 Active npm supply chain attack: keyv​@​6.0.0 and 13 other packages have been compromised. keyv alone gets 154M weekly downloads. The worm steals cloud and CI credentials, then uses stolen npm tokens to publish trojanized versions of more packages.
1169
Socket @socket.dev · 28/07/2026
🚨 Two Joyfill npm beta releases were compromised with an import-time implant that resolves encrypted payloads through Tron, Aptos, and BNB Smart Chain transactions to load a Node.js RAT: • @joyfill/layouts@0.1.2-2773.beta.0 • @joyfill/components@4.0.0-rc24-2773-beta.4
131
Socket @socket.dev · 27/07/2026
"Socket was the right fit for how we wanted our vulnerability management program to evolve. We wanted to move from reporting toward fixing and preventing, and the tooling we had before was not going to get us there." — Robert Phan, CISO, ID.​me
120
Socket @socket.dev · 09/07/2026
🚨 Socket detected a software supply chain compromise in @​injectivelabs/sdk-ts, a popular npm package with ~50,000 weekly downloads and 87 npm dependents. The malicious release hooks wallet key-derivation functions, records private keys and mnemonics, and exfiltrates them through fake telemetry.
141
Socket @socket.dev · 01/07/2026
Every package install brings third-party code into your app. On the Risky Biz podcast, Socket CEO @feross.bsky.social explains how AI coding agents are pulling in more dependencies, faster, often without a human in the loop. Watch the full episode: socket.dev/blog/risky-b...
2102
Socket @socket.dev · 19/06/2026
⭐️ Highlights: - Build custom roles from a base role or from scratch - Scope members to selected repos or all repos - See inherited vs. added permissions separately - Audit every access change ⚡️ Available now to all org admins: socket.dev/blog/introdu...
000
Socket @socket.dev · 19/06/2026
🚀 Socket Launch Week Day 5: Introducing Repository Access Permissions and Custom Roles. Custom Roles set what a user can do. Repository Access Permissions set which repos those actions apply to. Socket admins can now apply least-privilege access without forcing members into broad built-in roles.
131
Socket @socket.dev · 18/06/2026
Security teams can ask follow-up questions across alerts, package contents, threat intelligence, and determine org exposure in one place, without jumping between dashboards and package registries. Try Socket MCP → socket.dev/blog/socket-...
030
Socket @socket.dev · 18/06/2026
🚀 Socket Launch Week Day 4: Socket MCP is getting a massive update! You can now review org alerts, inspect package artifacts, investigate suspicious packages, and use the Socket threat feed directly from your AI assistant.
182
Socket @socket.dev · 17/06/2026
🚀 Launch Week Day 3: Socket Firewall now blocks malicious code editor extensions. VS Code and Open VSX extensions run inside developer environments with access to source code, terminals, credentials, and tokens. Now teams can block bad extensions before install or update.
1112
Socket @socket.dev · 16/06/2026
🚀 Day 2 of Socket Launch Week: We’re excited to introduce Manifest Alerts! Socket now detects supply chain risks found in project manifests, starting with missing lockfiles that can make dependency installs non-reproducible.
171
Socket @socket.dev · 15/06/2026
Create Linear issues from Socket alerts manually, or set up rules that automatically open, update, and close them based on alert activity. Set priority, assignee, and labels directly in the dashboard. ⚡️In beta now on Business + Enterprise: socket.dev/blog/socket-...
010
Socket @socket.dev · 19/05/2026
🚨 BREAKING: Socket is investigating an active npm supply chain attack compromising hundreds of packages in the @​antv ecosystem. The malicious publish wave appears tied to Mini Shai-Hulud and packages connected to the npm maintainer account atool.
23914
Socket @socket.dev · 14/05/2026
🚨 Socket detected malicious activity in newly published versions of node-ipc, an npm package with 822K weekly downloads. Affected versions: node-ipc@9.1.6 node-ipc@9.2.3 node-ipc@12.0.1 Socket’s AI scanner flagged the malware within ~3 minutes of publication.
182
Socket @socket.dev · 12/05/2026
🎉 Socket is proud to be named to the Rising in Cyber 2026 list by Notable Capital, recognizing 30 private cybersecurity startups selected by nearly 150 practicing CISOs and cybersecurity executives. socket.dev/blog/rising-...
0100
Socket @socket.dev · 30/04/2026
Affected users should block lightning versions 2.6.2 and 2.6.3, downgrade to 2.6.1, rotate exposed secrets, and audit GitHub activity for suspicious commits. The project's GitHub account appears to be compromised, as they are closing reports of the attack. More details: socket.dev/blog/lightni...
131
Socket @socket.dev · 30/04/2026
🚨 The popular PyPI package lightning has been compromised in a supply chain attack. Socket detected malicious code in versions 2.6.2 and 2.6.3 that executes automatically on import, downloads Bun, and runs an 11 MB obfuscated JavaScript payload designed to steal credentials.
142
Socket @socket.dev · 24/04/2026
Reachability for #PHP includes: → Full application + pre-computed reachability → Support for __call, DI containers, and middleware chains → Validated against #WordPress, #Laravel, #Symfony, #Twig, #Guzzle, and #PHPUnit 🐘 Learn more → socket.dev/blog/reachab...
040
Socket @socket.dev · 24/04/2026
🚀 Socket Launch Week Day 5: Reachability for PHP is now available in experimental! Cut through noisy CVEs with function-level call graph analysis that shows which vulnerabilities are actually reachable in your PHP apps.
110
Socket @socket.dev · 23/04/2026
At launch, Organization Notifications includes: → subscriptions for alert created, changed, and cleared events → filters for category, severity, priority, and repository → notification summaries built for triage ✨ Learn more: socket.dev/blog/organiz...
000
Socket @socket.dev · 23/04/2026
🚀 Socket Launch Week Day 3: We’re excited to launch Organization Notifications! This new feature helps teams stay on top of organization-level alert activity with filtered, batched notifications that make updates easier to route, review, and act on.
100
Socket @socket.dev · 21/04/2026
Heading to Google Cloud Next ’26 tomorrow? Join us at the startup showcase, where we'll be sharing a quick overview of Socket and a live demo. 🗓️ Wed, April 22nd | 2:45–3:45pm 📍 Startups Theater, Startups Hub www.googlecloudevents.com/next-vegas/s...
040
Socket @socket.dev · 21/04/2026
🚀 Day 2 of Socket Launch Week: Introducing Reports! Reports is a new page in the Socket dashboard for chart-based views of vulnerabilities, dependencies, and usage, built to make that data easier to share across reviews, presentations, and recurring reporting workflows.
131
Socket @socket.dev · 20/04/2026
Set rules for when Jira issues should be created, updated, or resolved, choose the right project, configure issue type, priority, labels, assignee, and additional fields, and keep everything in sync as alert state changes in Socket. ✨ See how it works→ socket.dev/blog/socket-...
010
Socket @socket.dev · 20/04/2026
🚀 We’re kicking off another Launch Week at Socket, with something new to share every day this week! First up: Socket for Jira is now available! This new integration lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.
121
Socket @socket.dev · 13/04/2026
"The big things that led us to Socket were: better data quality, higher relevance, and better coverage." - Timothy Smith, Security Engineering Manager, Cedar
100
Socket @socket.dev · 09/04/2026
"The whole software supply chain is built on blind trust. You're downloading code from random people on the internet that you've never met, and you're like, let's just run it." - @feross.bsky.social on TBPN talking about the Axios compromise. Full interview → socket.dev/blog/feross-...
086
Socket @socket.dev · 26/03/2026
TeamPCP has partnered with ransomware group Vect after exfiltrating ~300GB of credentials from CI/CD environments, targeting open source supply chains. “We will chain these compromises into devastating follow-on ransomware campaigns.” Details → socket.dev/blog/teampcp...
031
Socket @socket.dev · 23/03/2026
Aqua Security’s GitHub org was briefly taken over during the Trivy incident. Archived snapshots show attacker-created repos (e.g. tpcp-docs-*) with messages like “TeamPCP Owns Aqua Security,” indicating the attacker had write access to the org. Our post has been updated with more details:
010
Socket @socket.dev · 24/02/2026
AI agents are writing up to 90% of new production code. What does that mean for open source security? Socket CEO @feross.bsky.social joined the @riskybusiness.bsky.social podcast to break down this seismic shift & the growing risk to the software supply chain. Watch now→ socket.dev/blog/risky-b...
021
Socket @socket.dev · 24/02/2026
Join us on Feb 25 @ 10am PST for a fireside chat w/ Log4j maintainer @grobmeier.de and Socket CEO @feross.bsky.social on Log4Shell and the realities of maintaining critical OSS infrastructure. Watch live & get notified: LinkedIn → linkedin.com/events/74318... YouTube → youtube.com/watch?v=9-uV...
032
Socket @socket.dev · 23/02/2026
New Research: We uncovered 4 malicious NuGet packages targeting ASP.NET developers. A typosquatted “NCryptYo” dropper uses JIT hooking and a localhost proxy to steal Identity data and backdoor deployed apps. Full analysis: socket.dev/blog/four-ma...
100
Socket @socket.dev · 19/02/2026
Really cool to see @npmjs.bsky.social featuring more security information on package pages, including a link to Socket's analysis! 🤩 Here's what you'll find when you click through → socket.dev/blog/socket-... #NodeJS #JavaScript
094
Socket @socket.dev · 17/02/2026
Everyone's racing to build with AI agent skills. Decentralized repos, executable code = wide open attack surface. Socket is now securing skills on @vercel.com's skills.sh. We scan across Python, JS, and 10+ languages to catch malicious code before it reaches developers. socket.dev/blog/socket-...
082
Socket @socket.dev · 17/02/2026
The PHP ecosystem is massive, and so are the potential supply chain risks. Today’s launch brings best-in-class package security to Packagist and Composer workflows. We’re excited for the PHP community to try it and share feedback!
021
Socket @socket.dev · 17/02/2026
PHP developers can now: • Browse any Composer package’s security score & dependency insights • Generate SBOMs from composer.lock & composer.json • Detect malware, typosquatting, backdoors, and other risks with AI-powered analysis Learn more → socket.dev/blog/introdu...
231
Socket @socket.dev · 17/02/2026
🚀 Big news for #PHP developers! Socket now supports the PHP ecosystem with full Composer & @packagist.com integration. Search and explore packages, generate SBOMs from your Composer projects, and get proactive supply chain protection for your dependencies.
122
Socket @socket.dev · 28/01/2026
🦀 New on crates.io: RustSec advisories now appear on crate pages, alongside updates to Trusted Publishing support and CI trigger restrictions. Details → socket.dev/blog/crates-... #rustlang
000