Full-Time
Developer-focused platform securing software supply chains
No salary listed
Remote in USA
Remote
Remote-first; quarterly team off-sites.
Socket provides a developer-first security platform that protects software supply chains by securing open-source dependencies. It proactively detects and blocks malware and vulnerable packages in real time, integrating with developer workflows like GitHub so issues are surfaced as developers work. The product supports languages such as JavaScript, Python, and Go and offers a CLI and a browser extension to embed protection into existing toolchains. Unlike some security tools that scan after code is written or after deployment, Socket aims to stop threats before they are added to a codebase by embedding checks directly into developers’ workflows. The company's goal is to help organizations safely use open-source software by reducing the risk from compromised or outdated dependencies across the software development lifecycle.
Company Size
51-200
Company Stage
Series B
Total Funding
$64.6M
Headquarters
Wilmington, Delaware
Founded
2020
Help us improve and share your feedback! Did you find this helpful?
People at Socket who can refer or advise you
Company Equity
Health Insurance
Flexible Work Hours
Paid Holidays
Paid Parental Leave
Remote Work Options
Company Social Events
Socket has announced support for the PHP ecosystem, integrating Composer and Packagist into its software supply chain security platform. PHP developers can now search packages, generate Software Bills of Materials from Composer projects, and detect supply chain risks across dependencies. PHP powers roughly 75% of websites with a known server-side language. Packagist hosts over 440,000 packages with more than 169 billion installations since 2012, and Composer downloads exceed 2 billion packages monthly. Socket's AI-powered platform detects zero-day threats, typosquatting, backdoors and obfuscated code beyond traditional vulnerability scanning. Package search and browsing are available immediately, whilst SBOM generation and security scanning are in experimental release. Socket protects 14,000 organisations and 1.2 million repositories, securing over 2 million commits monthly and identifying 1,000 supply chain attacks weekly.
Security firm Socket recently revealed a massive campaign involving over 70 malicious npm and VS Code packages stealing data and crypto.
With the news following Socket's $40M Series B funding led by Abstract Ventures, Elad Gil and a16z, Zane Lackey, general partner at a16z, said "Socket's approach to open source security is simply better - it's proactive, precise, and built for how modern teams work.
Socket’s acquisition of Coana brings best-in-class reachability analysis to application security teams globally, cementing Socket’s position as the leader...
Cybersecurity researchers at Socket have uncovered a malicious npm package that hijacks server control during payment transactions.