惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

阮一峰的网络日志
阮一峰的网络日志
雷峰网
雷峰网
Last Week in AI
Last Week in AI
T
Tailwind CSS Blog
V
Visual Studio Blog
Jina AI
Jina AI
博客园 - 司徒正美
The Cloudflare Blog
Hugging Face - Blog
Hugging Face - Blog
博客园_首页
S
SegmentFault 最新的问题
博客园 - 三生石上(FineUI控件)
有赞技术团队
有赞技术团队
小众软件
小众软件
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
美团技术团队
博客园 - 【当耐特】
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
WordPress大学
WordPress大学
爱范儿
爱范儿
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏

Socket

Fake Corepack Site Distributes Infostealer and Proxyware to ... Large-Scale GitHub Actions Abuse Powers a Distributed cPanel... New Study Identifies 53 Slopsquatting Targets Across 5 Front... White House Launches Gold Eagle Initiative to Manage Surge i... Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu... Next.js moves to scheduled security releases - Socket 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windo... Compromised npm Packages in the AsyncAPI Namespace Deliver M... jscrambler npm Package Compromised in Supply Chain Attack - ... Fake Braintree NuGet Package Skims Credit Cards and Harvests... Compromised Injective SDK npm Package Exfiltrates Wallet Key... npm v12 Ships With Install Scripts Off by Default, Begins De... Malicious Go Module Exposes GitHub Malware Lure Network Span... pnpm 11.10 Hardens Registry Authentication to Block Token Re... Coordinated npm and PyPI Campaign Typosquats Popular Secure ... Node.js Considers Public Workflow for Security Reports Amid ... PolinRider: North Korea-Linked Supply Chain Campaign Expands... Risky Biz Podcast: AI Agents Are Raising the Stakes for Soft... Chrome and Firefox Extensions Posing as Free VPNs Add Clipbo... Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages - S... Rolldown Pulls Rust React Compiler Integration After Binary ... Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and Git... Frontier AI Is Now Critical Infrastructure - Socket The Code You Didn't Write Is Still Yours to Defend - Socket GitHub Actions Checkout Now Blocks Risky pull_request_target... Introducing Repository Access Permissions and Custom Roles -... Socket MCP Adds Org Alerts, Threat Feed Review, and Package ... Socket Firewall Now Blocks Malicious VS Code and Open VSX Ex... 140+ Mastra npm Packages Compromised in Coordinated Supply C... npm Package Uses Prompt Injection and Token Flooding to Disr...
Socket Raises $60M Series C at a $1B Valuation to Help En...
Feross Aboukhadijeh · 2026-05-20 · via Socket

Led by Thrive Capital, the round brings Socket to unicorn status as enterprises race to adopt AI coding tools and look for ways to secure the third-party dependencies entering production without slowing down

SAN FRANCISCO, May 20, 2026 – Socket today announced it has raised $60 million in Series C funding at a $1 billion valuation. Led by Thrive CapitaI, with participation from a16z, Abstract Ventures, and Capital One Ventures, the round will support Socket’s next phase of growth as more organizations race to adopt AI across software development and look for better ways to secure the open source code entering production without sacrificing engineering velocity.

Founded in 2020, Socket counts Anthropic, xAI, Replit, Cursor, Figma, Vercel, Gusto, Mercado LIbre, and Cribl among its customers, as well as Fortune 100 companies in financial services and global media.

AI is accelerating software development, but it is also increasing the volume of open source code entering production. For enterprises, secure software delivery now depends on being able to evaluate that code without slowing down development.

That shift is moving software supply chain security higher on the enterprise agenda. In the OWASP Top 10:2025 community survey, software supply chain failures ranked as the top concern. A 2025 Linux Foundation report found that only 36% of organizations evaluate the direct dependencies of open source code before using a new component.

The recent compromise of Axios, one of the most widely used packages in the JavaScript ecosystem, showed how quickly malicious code in a popular dependency can spread. Socket identified the malicious dependency within six minutes and moved quickly to help users and customers block the package from entering their environments. Within 24 hours, more than 2,000 organizations had onboarded to its platform.

Socket analyzes the behavior of open source dependencies before they enter an organization’s codebase. Rather than relying only on known vulnerability databases, which typically surface issues after public disclosure, Socket is built to identify malicious behavior and other signs of supply chain risk in real time, including novel attacks that have yet to be catalogued. The platform combines AI-assisted analysis with human verification to help teams identify malicious behavior, prioritize exploitable vulnerabilities, and remediate dependency risk.

“AI is changing how software gets built at every level,” said Feross Aboukhadijeh, founder and CEO of Socket. “Teams are moving faster, more code is being generated, and more of what ends up in production now comes from outside the company. The hard part is keeping that speed without losing visibility into what’s actually getting shipped, and that’s where Socket comes in.”

“Security is changing radically and rapidly,” said Philip Clark, Partner at Thrive Capital. “Legacy tools were designed to react to known vulnerabilities and assumed there was sufficient time to prevent a breach. Today, AI models can identify vulnerabilities so well and so quickly that this is no longer an option. We need tools like Socket that can identify threats in third party code before they enter production and we believe there is no team better positioned to meet that demand.”

About Socket

Socket is a developer-first security platform that protects organizations from software supply chain attacks. By analyzing open source dependencies for malicious behavior, Socket helps teams identify and block threats before they reach production.

2810 N Church St., Suite 71517, Wilmington,DE, 19802