Log inSign up
Log inSign up
Socket
3,436 posts
Socket profile banner
@SocketSecurity

Socket

@SocketSecurity
Socket is the #1 software supply chain security platform. Next-gen SCA + SBOM + 0-day prevention. LOVED BY DEVELOPERS. 👀 @npm_malware
https://socket.dev/careers
socket.dev
Joined November 2021
4,605 Following
22.6k Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @SocketSecurity
    Socket
    @SocketSecurity
    22 May
    Today is a big day for Socket.
    @feross
    Feross
    Socket
    @feross
    20 May
    Today is a big day for @SocketSecurity. We just raised a $60M Series C at a $1B valuation, led by @ThriveCapital with participation from @a16z, @AbstractVC, and @CapitalOne Ventures. Total funding is now $125M. Four years ago, we started Socket because open source dependencies
    4
  • @SocketSecurity
    Socket
    @SocketSecurity
    5h
    Update: Socket has identified more than 500 GitHub accounts that committed the malicious GhostAction workflow to tens of thousands of repositories since October 7, including organization-owned repositories reached through compromised contributors.
    @SocketSecurity
    Socket
    @SocketSecurity
    10h
    🚨 A new GhostAction wave has hit hundreds of GitHub repos, including Uber’s athenadriver and Pyxel. Attackers used compromised maintainer accounts to plant fake “security audit” workflows that steal GitHub Actions secrets.
  • @SocketSecurity
    Socket
    @SocketSecurity
    8h
    .@arxiv: "Our moderators are observing an increase in thin papers of narrow scope, as well as ‘salami’ papers, where a single work is broken up and submitted as a set of smaller papers. There is also a marked increase in dense, AI-written papers."
    arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
    From socket.dev
  • @SocketSecurity
    Socket
    @SocketSecurity
    10h
    🚨 A new GhostAction wave has hit hundreds of GitHub repos, including Uber’s athenadriver and Pyxel. Attackers used compromised maintainer accounts to plant fake “security audit” workflows that steal GitHub Actions secrets.
    2
  • @SocketSecurity
    Socket
    @SocketSecurity
    8 Oct
    🚨 Tensorlake’s npm SDK (12K weekly downloads) was compromised in a ChainDrop / Shai-Hulud attack. Version 0.5.144 contains a credential-stealing worm with a dead-man switch designed to execute attacker code when a stolen GitHub token is revoked. socket.dev/blog/tensorlak…
    2
Edit with