Socket is a developer-first security platform that detects and blocks malicious and vulnerable open source packages before they reach a developer's laptop, a CI pipeline or production. Rather than matching against known vulnerability databases, it analyzes the actual behavior of packages across the major ecosystems (npm, PyPI, Maven, Go, NuGet, RubyGems and more; Feross says 19 in total) and flags typosquats, backdoors, obfuscated code and compromised maintainer accounts in real time. It ships as a GitHub app that comments on pull requests, a CLI, and Socket Firewall, which is free for everyone and blocks bad packages at install time. Since 2025 the platform also includes reachability analysis from the Coana acquisition, which filters out up to 80% of irrelevant CVEs, and since 2026 coverage of browser extensions, editor plug-ins, MCP servers and AI tools from the Secure Annex acquisition.
As of the May 2026 Series C, Socket protects more than 27,000 organizations (up from 7,500 in October 2024), 1.5 million repositories and 11.6 million commits a month, and blocks over 10,000 supply chain attacks a week. Customers include Anthropic, xAI, Replit, Cursor, Vercel, Figma, Gusto, Mercado Libre and Cribl. In March 2026 the team was first to flag the backdoor in Axios, a library downloaded over 100 million times a week, within six minutes of it hitting npm. The company was founded in 2020, launched publicly in May 2022, and in August 2026 became available through the AWS Security Hub Extended plan.