New:Introducing Socket Scanning for VS Code Marketplace Extensions.Learn more →
Get Started

Secure OSS Dependencies

Socket for Open Source Security

Quickly evaluate the security and health of any open source package. Unlike a traditional vulnerability scanner, Socket can detect an active supply chain attack and help you block it. Socket detects over 70 issues in open source code for comprehensive protection.

Explore Integrations
Book a Demo

Call us at (844) SOCKET-0

Beyond CVE Scanning

What is Open Source Security?

Open source code makes up more than 90% of modern software projects, with many apps spamming 10,000+ dependencies. This makes it easy for attackers to use open source as a vector for attacks where open source packages registries are frequently the target of malware. Traditional vulnerability scanners cannot detect active supply chain attacks. Socket's free GitHub app safeguards your open source code from both vulnerable and malicious dependencies.

Install GitHub AppContact Sales
Socket Website

We protect you from vulnerable and malicious packages

github.com/oyamamas/cloudexec

v0.0.0-20261008224945-4fc0ed2d537d

Live on go

Blocked by Socket

This module is a high-risk, weaponized client that enables remote shell command execution by injecting the caller-controlled flags["exec"] into /bin/sh -c inside a remote agent service-check registration over HTTP. It then verifies execution via returned check output and cleans up by deregistering the service. Even if intended for authorized testing, as a reusable dependency it provides a clear exploitation primitive and should be treated as extremely dangerous.

honeybee-doe2

0.25.2

Live on pypi

Blocked by Socket

This module is largely a domain-specific parser/converter, but it contains a high-severity security flaw: it uses eval() on content derived from untrusted INP/LAYERS text. When operating on untrusted files or strings, this creates a realistic path to arbitrary Python expression evaluation (supply-chain sabotage / code execution risk). Additional concerns include regex-based broad matching, extensive exception suppression, and an apparent undefined return variable (material), which may impair reliability and detection of tampering. Recommend removing eval() and replacing with a safe parser (e.g., literal_eval with strict validation) if list syntax is intended, plus tighten parsing and fail loudly on malformed inputs.

@profoundlogic/coderflow-server

0.15.3-dev.10

by profoundlogic

Live on npm

Blocked by Socket

The fragment is heavily obfuscated and contains a deterministic logic defect that appears to sabotage documentation loading: walkMarkdown always returns an incompatible object when processing a directory entry, causing loadRoot to fail. It does not show data theft or conventional malware behavior, but the apparent intentional disruption warrants treating the code as suspicious.

deposit-limit-fe

100.100.106

by dot2027

Live on npm

Blocked by Socket

The module automatically transmits host and npm configuration metadata to a hardcoded remote IP over plain HTTP. This is suspicious data disclosure and should be reviewed before use.

nitro-bundled-dep

99.0.1

by xwise898

Live on npm

Blocked by Socket

This code sends identifying host and execution-environment metadata to a hardcoded external endpoint when executed directly. The behavior is consistent with undisclosed telemetry and presents a data-leak risk; no other malicious behavior is evident in the fragment.

asepxyz-baileys

0.0.1-security

by npm

Live on npm

Blocked by Socket

Malicious code in asepxyz-baileys (npm) Source: ghsa-malware (5b237efd2362cabb19a1d538927608d053a0fbec1990177bf681e1984f3637c6) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

py2ops

2.2.1

Live on pypi

Blocked by Socket

The fragment has a high-risk remote code execution design: it retrieves an encoded Python payload from remote servers and executes it. It also sends user-entered unlock strings to a server and performs local file deletion when requested. The supplied text is syntactically invalid, but the intended behavior is strongly suspicious and should not be run without verifying the package and servers.

kmf-bootstrap

100.100.103

by dot2027

Live on npm

Blocked by Socket

Malicious code in kmf-bootstrap (npm) Source: ossf-package-analysis (4a4e085f9bdddf6800e613b7cdfeb6b2481b2fe9bf0ccb2a5b1bffad9538194b) The OpenSSF Package Analysis project identified 'kmf-bootstrap' @ 100.100.102 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

kube-q

1.6.3

Live on pypi

Blocked by Socket

This module exposes a WebSocket-accessible pseudo-terminal proxy that spawns a configurable command (PTY_CMD/PTY_ARGS) and bridges arbitrary client input directly into the PTY while streaming all process output back to the client. Authentication is disabled when PTY_AUTH_TOKEN is not set, and there are no additional access controls (no origin/rate limiting). The merged .env/process.env environment is passed into the child process, increasing the chance of secret exposure. Overall, this is a high-impact remote command/control surface consistent with backdoor-like behavior; use only with strong deployment hardening and guaranteed authentication/segmentation.

outfit418-backup-ratting

0.11.1

Live on pypi

Blocked by Socket

This module contains a critical security vulnerability: it performs pickle.load on an uploaded file in the dashboard() POST handler. If an attacker can influence or obtain access to that endpoint (e.g., through compromised/abused privileged access), crafted pickle payloads can lead to arbitrary code execution in the web process. The deserialized content also directly drives Celery task fan-out and background import behavior, amplifying impact. Other endpoints largely follow standard Django patterns with validated inputs/ORM usage, but the unsafe deserialization makes overall security risk extremely high for this package/module fragment.

nested-lib

1.0.0

by xwise898

Live on npm

Blocked by Socket

This code performs undisclosed telemetry-style transmission of host and installation metadata to a hardcoded external IP over unencrypted HTTP. Treat as suspicious data exfiltration and review the package's execution and installation context.

@juzi/wechaty

1.0.169

by GitHub Actions

Live on npm

Blocked by Socket

High-severity supply-chain/security risk. This module implements a remote control plane over WebSocket in which the server can dynamically create and install executable JavaScript using new AsyncFunction(...args, source) and later execute it on local 'message' events (remote code execution/backdoor-like capability). It also includes a server-triggered process termination (process.exit(0)) and forwards multiple Wechaty-derived events upstream. Additional concerns include plaintext token logging and possible use of unencrypted ws:// transport depending on configuration. If the server endpoint is not strictly trusted and authenticated end-to-end, the overall security posture is critical.

mythos0-labs.graphics-h-runner

1.5.23

by mythos0-labs

Live on vscode

Blocked by Socket

Despite primarily benign-looking canvas/ticker and input dispatch functionality, this module contains strong supply-chain sabotage behavior: on a hostname match (constructed/obfuscated fragments), it waits ~3 minutes and then overwrites document.body.innerHTML with a prebuilt defacement/error page containing external links and contact info. No direct exfiltration is visible here, but the impact of full-page DOM replacement is severe.

outfit418-backup-ratting

0.11.1

Live on pypi

Blocked by Socket

This module contains a critical security vulnerability: it performs pickle.load on an uploaded file in the dashboard() POST handler. If an attacker can influence or obtain access to that endpoint (e.g., through compromised/abused privileged access), crafted pickle payloads can lead to arbitrary code execution in the web process. The deserialized content also directly drives Celery task fan-out and background import behavior, amplifying impact. Other endpoints largely follow standard Django patterns with validated inputs/ORM usage, but the unsafe deserialization makes overall security risk extremely high for this package/module fragment.

github.com/opengrep/opengrep-rules

v0.0.0-20250126154113-f1d2b562b414

Live on go

Blocked by Socket

The fragment enables remote command execution over SSH and passes untrusted input directly into exec_command, which can lead to arbitrary command execution on the target host. It also runs a recursive listing of the remote root directory, consistent with reconnaissance. No explicit exfiltration, credential theft, or obfuscation is present in the provided code, but the direct command-injection-like usage makes this snippet strongly security-sensitive and potentially malicious depending on runtime context.

asepxyz-eslint-config

0.0.1-security

by npm

Live on npm

Blocked by Socket

Malicious code in asepxyz-eslint-config (npm) Source: ghsa-malware (d9e873795c4634852530066ca11f554da84043934f246df7b3edbe868ea343ef) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

github.com/aliyun/qwen-dianjin

v0.0.0-20260828100220-9a0d0b871e8b

Live on go

Blocked by Socket

The fragment is a set of deliberately malicious test or prompt-injection scenarios, not executable code as shown. It contains encoded instructions for credential and private-data exfiltration, system reconnaissance, and security-policy changes. Risk depends on whether a downstream agent or program executes or follows these instructions.

some-very-long-package-name

2.0.1

by xwise898

Live on npm

Blocked by Socket

The code exfiltrates host and package-installation metadata to a hardcoded external endpoint over unencrypted HTTP. This is suspicious and poses a privacy and supply-chain risk; do not use without verifying the endpoint and intended telemetry.

@myorder-frontend-commons/analytics

0.2.0

by piotrbsf

Live on npm

Blocked by Socket

This code deliberately collects identifying system, user, working-directory, runtime, package, and CI metadata and transmits it to external callback endpoints. Treat it as malicious or unauthorized telemetry unless independently verified as an explicitly authorized test; do not run it in a sensitive environment.

@myorder-frontend-commons/analytics

100.0.0

by piotrbsf

Live on npm

Blocked by Socket

This code performs unsolicited transmission of host, user, environment, and package metadata to external callback hosts when loaded. This is a clear data-exfiltration behavior and is unrelated to ordinary analytics functionality in the shown fragment; treat it as malicious or unauthorized unless independently verified as an explicitly authorized test.

kmf-vendor-pack

99.0.0

by dot2027

Live on npm

Blocked by Socket

The postinstall script performs automatic data exfiltration of machine-identifying information (hostname and username) to a third-party server during installation. This is a high-risk privacy and security issue — it can be used for tracking, reconnaissance, or to fingerprint compromised hosts. Unless you explicitly trust the package and the remote endpoint, do not install it in sensitive environments.

py2ops

2.2

Live on pypi

Blocked by Socket

High risk: this launcher sends interactive input to a remote unlock service and executes arbitrary Python code downloaded from that service without integrity verification. Treat the remote service and payload as fully trusted only if independently verified; otherwise, do not run it. The fragment has syntax errors as supplied, which may indicate omitted or altered content.

{4d3ca665-58d3-43b1-8f94-69071518b568}

177.0.1

by anonymous-72dca32210bd958294b79a20171383c5

Live on firefox

Blocked by Socket

Credential/seed-phrase stealing code in a fake crypto-wallet login UI. The script attaches listeners to seed-phrase word fields (.js-login-field), a full seed-phrase textarea (#id_8c01e75a) and a passphrase field (#id_670c9db8). On every input event it debounces 1000ms and then passes the raw secret material to collectMetrics({data: <seed phrase | passphrase>}) — the concatenated 12/24-word recovery phrase, the raw seed string, and the wallet passphrase. It also intercepts paste events (preventDefault + clipboardData.getData('text')), normalizes and splits the clipboard content into up to 24 words, autofills all word fields, and then forwards the reassembled phrase to collectMetrics; an additional handler synthesizes fake 'paste' events for insertFromPaste input to route mobile/programmatic input through the same capture path. The form's submit handler performs no authentication at all: it always calls preventDefault(), disables the submit button, and unconditionally reveals the error message and marks the input as invalid, confirming the page exists solely to capture secrets rather than to log a user in. collectMetrics is defined outside this file (login-key.js / app.js / background.js) and constitutes the exfiltration sink. Any wallet seed phrase or passphrase entered into this UI must be considered fully compromised and the associated funds moved immediately.

github.com/opengrep/opengrep-rules

v0.0.0-20250126154113-f1d2b562b414

Live on go

Blocked by Socket

This module contains multiple critically dangerous routes that call require() with attacker-controlled values from req.query and req.body, then execute the loaded exports and return their results to the client. If an attacker can influence the module specifier/path that require() resolves, the application can load and execute attacker-chosen code with access to req/res, creating an RCE-like compromise pathway. Hardcoded routes using 'lib/func.js' are safer but do not remediate the overall risk due to the other dynamic endpoints.

nitro-cjs-requirer

1.0.0

by xwise898

Live on npm

Blocked by Socket

This code performs unexplained outbound telemetry to a hardcoded IP address, disclosing host and package-path metadata over plaintext HTTP. This is suspicious and consistent with unauthorized data collection; avoid running it unless the beacon is known and explicitly authorized.

github.com/oyamamas/cloudexec

v0.0.0-20261008224945-4fc0ed2d537d

Live on go

Blocked by Socket

This module is a high-risk, weaponized client that enables remote shell command execution by injecting the caller-controlled flags["exec"] into /bin/sh -c inside a remote agent service-check registration over HTTP. It then verifies execution via returned check output and cleans up by deregistering the service. Even if intended for authorized testing, as a reusable dependency it provides a clear exploitation primitive and should be treated as extremely dangerous.

honeybee-doe2

0.25.2

Live on pypi

Blocked by Socket

This module is largely a domain-specific parser/converter, but it contains a high-severity security flaw: it uses eval() on content derived from untrusted INP/LAYERS text. When operating on untrusted files or strings, this creates a realistic path to arbitrary Python expression evaluation (supply-chain sabotage / code execution risk). Additional concerns include regex-based broad matching, extensive exception suppression, and an apparent undefined return variable (material), which may impair reliability and detection of tampering. Recommend removing eval() and replacing with a safe parser (e.g., literal_eval with strict validation) if list syntax is intended, plus tighten parsing and fail loudly on malformed inputs.

@profoundlogic/coderflow-server

0.15.3-dev.10

by profoundlogic

Live on npm

Blocked by Socket

The fragment is heavily obfuscated and contains a deterministic logic defect that appears to sabotage documentation loading: walkMarkdown always returns an incompatible object when processing a directory entry, causing loadRoot to fail. It does not show data theft or conventional malware behavior, but the apparent intentional disruption warrants treating the code as suspicious.

deposit-limit-fe

100.100.106

by dot2027

Live on npm

Blocked by Socket

The module automatically transmits host and npm configuration metadata to a hardcoded remote IP over plain HTTP. This is suspicious data disclosure and should be reviewed before use.

nitro-bundled-dep

99.0.1

by xwise898

Live on npm

Blocked by Socket

This code sends identifying host and execution-environment metadata to a hardcoded external endpoint when executed directly. The behavior is consistent with undisclosed telemetry and presents a data-leak risk; no other malicious behavior is evident in the fragment.

asepxyz-baileys

0.0.1-security

by npm

Live on npm

Blocked by Socket

Malicious code in asepxyz-baileys (npm) Source: ghsa-malware (5b237efd2362cabb19a1d538927608d053a0fbec1990177bf681e1984f3637c6) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

py2ops

2.2.1

Live on pypi

Blocked by Socket

The fragment has a high-risk remote code execution design: it retrieves an encoded Python payload from remote servers and executes it. It also sends user-entered unlock strings to a server and performs local file deletion when requested. The supplied text is syntactically invalid, but the intended behavior is strongly suspicious and should not be run without verifying the package and servers.

kmf-bootstrap

100.100.103

by dot2027

Live on npm

Blocked by Socket

Malicious code in kmf-bootstrap (npm) Source: ossf-package-analysis (4a4e085f9bdddf6800e613b7cdfeb6b2481b2fe9bf0ccb2a5b1bffad9538194b) The OpenSSF Package Analysis project identified 'kmf-bootstrap' @ 100.100.102 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

kube-q

1.6.3

Live on pypi

Blocked by Socket

This module exposes a WebSocket-accessible pseudo-terminal proxy that spawns a configurable command (PTY_CMD/PTY_ARGS) and bridges arbitrary client input directly into the PTY while streaming all process output back to the client. Authentication is disabled when PTY_AUTH_TOKEN is not set, and there are no additional access controls (no origin/rate limiting). The merged .env/process.env environment is passed into the child process, increasing the chance of secret exposure. Overall, this is a high-impact remote command/control surface consistent with backdoor-like behavior; use only with strong deployment hardening and guaranteed authentication/segmentation.

outfit418-backup-ratting

0.11.1

Live on pypi

Blocked by Socket

This module contains a critical security vulnerability: it performs pickle.load on an uploaded file in the dashboard() POST handler. If an attacker can influence or obtain access to that endpoint (e.g., through compromised/abused privileged access), crafted pickle payloads can lead to arbitrary code execution in the web process. The deserialized content also directly drives Celery task fan-out and background import behavior, amplifying impact. Other endpoints largely follow standard Django patterns with validated inputs/ORM usage, but the unsafe deserialization makes overall security risk extremely high for this package/module fragment.

nested-lib

1.0.0

by xwise898

Live on npm

Blocked by Socket

This code performs undisclosed telemetry-style transmission of host and installation metadata to a hardcoded external IP over unencrypted HTTP. Treat as suspicious data exfiltration and review the package's execution and installation context.

@juzi/wechaty

1.0.169

by GitHub Actions

Live on npm

Blocked by Socket

High-severity supply-chain/security risk. This module implements a remote control plane over WebSocket in which the server can dynamically create and install executable JavaScript using new AsyncFunction(...args, source) and later execute it on local 'message' events (remote code execution/backdoor-like capability). It also includes a server-triggered process termination (process.exit(0)) and forwards multiple Wechaty-derived events upstream. Additional concerns include plaintext token logging and possible use of unencrypted ws:// transport depending on configuration. If the server endpoint is not strictly trusted and authenticated end-to-end, the overall security posture is critical.

mythos0-labs.graphics-h-runner

1.5.23

by mythos0-labs

Live on vscode

Blocked by Socket

Despite primarily benign-looking canvas/ticker and input dispatch functionality, this module contains strong supply-chain sabotage behavior: on a hostname match (constructed/obfuscated fragments), it waits ~3 minutes and then overwrites document.body.innerHTML with a prebuilt defacement/error page containing external links and contact info. No direct exfiltration is visible here, but the impact of full-page DOM replacement is severe.

outfit418-backup-ratting

0.11.1

Live on pypi

Blocked by Socket

This module contains a critical security vulnerability: it performs pickle.load on an uploaded file in the dashboard() POST handler. If an attacker can influence or obtain access to that endpoint (e.g., through compromised/abused privileged access), crafted pickle payloads can lead to arbitrary code execution in the web process. The deserialized content also directly drives Celery task fan-out and background import behavior, amplifying impact. Other endpoints largely follow standard Django patterns with validated inputs/ORM usage, but the unsafe deserialization makes overall security risk extremely high for this package/module fragment.

github.com/opengrep/opengrep-rules

v0.0.0-20250126154113-f1d2b562b414

Live on go

Blocked by Socket

The fragment enables remote command execution over SSH and passes untrusted input directly into exec_command, which can lead to arbitrary command execution on the target host. It also runs a recursive listing of the remote root directory, consistent with reconnaissance. No explicit exfiltration, credential theft, or obfuscation is present in the provided code, but the direct command-injection-like usage makes this snippet strongly security-sensitive and potentially malicious depending on runtime context.

asepxyz-eslint-config

0.0.1-security

by npm

Live on npm

Blocked by Socket

Malicious code in asepxyz-eslint-config (npm) Source: ghsa-malware (d9e873795c4634852530066ca11f554da84043934f246df7b3edbe868ea343ef) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

github.com/aliyun/qwen-dianjin

v0.0.0-20260828100220-9a0d0b871e8b

Live on go

Blocked by Socket

The fragment is a set of deliberately malicious test or prompt-injection scenarios, not executable code as shown. It contains encoded instructions for credential and private-data exfiltration, system reconnaissance, and security-policy changes. Risk depends on whether a downstream agent or program executes or follows these instructions.

some-very-long-package-name

2.0.1

by xwise898

Live on npm

Blocked by Socket

The code exfiltrates host and package-installation metadata to a hardcoded external endpoint over unencrypted HTTP. This is suspicious and poses a privacy and supply-chain risk; do not use without verifying the endpoint and intended telemetry.

@myorder-frontend-commons/analytics

0.2.0

by piotrbsf

Live on npm

Blocked by Socket

This code deliberately collects identifying system, user, working-directory, runtime, package, and CI metadata and transmits it to external callback endpoints. Treat it as malicious or unauthorized telemetry unless independently verified as an explicitly authorized test; do not run it in a sensitive environment.

@myorder-frontend-commons/analytics

100.0.0

by piotrbsf

Live on npm

Blocked by Socket

This code performs unsolicited transmission of host, user, environment, and package metadata to external callback hosts when loaded. This is a clear data-exfiltration behavior and is unrelated to ordinary analytics functionality in the shown fragment; treat it as malicious or unauthorized unless independently verified as an explicitly authorized test.

kmf-vendor-pack

99.0.0

by dot2027

Live on npm

Blocked by Socket

The postinstall script performs automatic data exfiltration of machine-identifying information (hostname and username) to a third-party server during installation. This is a high-risk privacy and security issue — it can be used for tracking, reconnaissance, or to fingerprint compromised hosts. Unless you explicitly trust the package and the remote endpoint, do not install it in sensitive environments.

py2ops

2.2

Live on pypi

Blocked by Socket

High risk: this launcher sends interactive input to a remote unlock service and executes arbitrary Python code downloaded from that service without integrity verification. Treat the remote service and payload as fully trusted only if independently verified; otherwise, do not run it. The fragment has syntax errors as supplied, which may indicate omitted or altered content.

{4d3ca665-58d3-43b1-8f94-69071518b568}

177.0.1

by anonymous-72dca32210bd958294b79a20171383c5

Live on firefox

Blocked by Socket

Credential/seed-phrase stealing code in a fake crypto-wallet login UI. The script attaches listeners to seed-phrase word fields (.js-login-field), a full seed-phrase textarea (#id_8c01e75a) and a passphrase field (#id_670c9db8). On every input event it debounces 1000ms and then passes the raw secret material to collectMetrics({data: <seed phrase | passphrase>}) — the concatenated 12/24-word recovery phrase, the raw seed string, and the wallet passphrase. It also intercepts paste events (preventDefault + clipboardData.getData('text')), normalizes and splits the clipboard content into up to 24 words, autofills all word fields, and then forwards the reassembled phrase to collectMetrics; an additional handler synthesizes fake 'paste' events for insertFromPaste input to route mobile/programmatic input through the same capture path. The form's submit handler performs no authentication at all: it always calls preventDefault(), disables the submit button, and unconditionally reveals the error message and marks the input as invalid, confirming the page exists solely to capture secrets rather than to log a user in. collectMetrics is defined outside this file (login-key.js / app.js / background.js) and constitutes the exfiltration sink. Any wallet seed phrase or passphrase entered into this UI must be considered fully compromised and the associated funds moved immediately.

github.com/opengrep/opengrep-rules

v0.0.0-20250126154113-f1d2b562b414

Live on go

Blocked by Socket

This module contains multiple critically dangerous routes that call require() with attacker-controlled values from req.query and req.body, then execute the loaded exports and return their results to the client. If an attacker can influence the module specifier/path that require() resolves, the application can load and execute attacker-chosen code with access to req/res, creating an RCE-like compromise pathway. Hardcoded routes using 'lib/func.js' are safer but do not remediate the overall risk due to the other dynamic endpoints.

nitro-cjs-requirer

1.0.0

by xwise898

Live on npm

Blocked by Socket

This code performs unexplained outbound telemetry to a hardcoded IP address, disclosing host and package-path metadata over plaintext HTTP. This is suspicious and consistent with unauthorized data collection; avoid running it unless the beacon is known and explicitly authorized.

Get Visibility Into Open Source Dependencies with Real-Time Security Feedback

Proactively search and detect dependencies across repositories in your organization, with actionable insights for your projects and SBOMs

Organization Dashboard

Open Source Supply Chain Attack Prevention

Block Malware and Typosquatting

Block emerging malware threats, including intentionally maintainer-added updates, along with packages that differ in name by only a few characters..

Detect Privileged API Usage

Get alerted when a dependency update introduces new risky API usage - filesystem, network, child_process, eval().

Detect Hidden Code

Detect obfuscated, minified, or hidden code.

Detect Suspicious Updates

Socket detects the sudden inclusion of a new maintainer, updates with telemetry or protestware added, dependencies pulled in from a remote git URL, and much more.

We help security teams work more efficiently

Cut through the noise and focus on real threats.

Get actionable alerts for the supply chain risks that matter. Socket highlights risky dependencies directly within the developer workflow.