https://socket.dev/blog/series-b | New window | Huge News!Announcing our $40M Series B led by Abstract Ventures.Learn More → |
https://socket.dev/ | | IMG-ALT Socket |
https://socket.dev/auth/login | | Sign in |
https://socket.dev/demo | New window | Demo |
https://socket.dev/github-app | | Install |
https://socket.dev/ | Text duplicate | IMG-ALT Socket |
https://socket.dev/features | | What is Socket? |
/features/github | | Socket for GitHub Detect suspicious packages in PRs |
https://socket.dev/features/cli | | Socket CLI Use Socket from the command line |
/features/web-extension | | Socket Web Extension Use Socket from your browser |
/features/dependency-search | | Socket Dependency Search Find any package for your project |
/features/optimize | | Socket Optimize Optimize your dependencies |
https://socket.dev/integrations | | All Integrations |
https://socket.dev/integrations | | Source Control |
https://socket.dev/integrations | | Languages |
https://socket.dev/integrations | | Ticketing & Messaging |
https://socket.dev/integrations | | Package Managers |
https://socket.dev/integrations | | SIEM |
https://docs.socket.dev/ | New window External Subdomain | Docs Want to read all the docs? Start here |
https://socket.dev/customers | | Customers Check out our customer stories |
https://socket.dev/blog | | Blog Keep up to date with all the news |
https://socket.dev/changelog | | Changelog Latest updates and enhancements |
https://socket.dev/faq | | FAQ Answers to common questions |
https://socket.dev/alerts | | Package Alerts Learn about all Socket alerts |
https://socket.dev/glossary | | Glossary Open source and security terms |
https://socket.dev/blog | | All blog posts |
/blog/category/security-news | | Security News |
/blog/category/news | | Company News |
/blog/category/engineering | | Engineering |
/blog/category/product | | Product |
/blog/category/research | | Research |
/blog/category/security | | Application Security |
https://socket.dev/customers | | All customers |
/case-study/vercel | | Vercel |
/case-study/drata | | Drata |
/case-study/Replit | | Replit |
/case-study/metamask | | MetaMask |
https://socket.dev/about | | About Why we built Socket |
https://socket.dev/love | | Love See why developers love Socket |
https://socket.dev/careers | | Careers Join our team |
https://socket.dev/about | | Investors Learn about our investors |
https://socket.dev/security | | Security Our security practices |
/compare/socket-vs-snyk | | Socket vs Snyk |
/compare/socket-vs-dependabot | | Socket vs Dependabot |
/compare/socket-vs-semgrep | | Socket vs Semgrep |
/compare/socket-vs-endor-labs | | Socket vs EndorLabs |
/use-case/open-source-security | | Socket for Open Source Security |
https://socket.dev/use-case/sca | | Socket for SCA |
/use-case/supply-chain-attack-... | | Socket for Supply Chain Attack Prevention |
/blog/announcing-soc-2-type-2-... | | SOC 2 Type 2 |
https://socket.dev/blog/series-b | | Raised $65M |
/blog/socket-recognized-on-for... | | Fortune Cyber 60 |
https://socket.dev/customers | | Top Customers |
/blog/category/news | Text duplicate | Company News |
https://socket.dev/pricing | | Pricing |
https://socket.dev/love | | Love |
https://docs.socket.dev/ | New window External Subdomain | Docs |
https://socket.dev/auth/login | Text duplicate | Sign in |
https://socket.dev/demo | New window Text duplicate | Demo |
https://socket.dev/github-app | Text duplicate | Install |
https://socket.dev/github-app | | Install GitHub App |
https://socket.dev/demo | New window | Book a Demo |
/npm/package/jquery | | jquery timmywil published 3.7.1 • last year |
/npm/package/left-pad | | left-pad stevemao published 1.3.0 • 7 years ago |
/npm/package/react | | react react-bot published 19.0.0 • last month |
/npm/package/catapulse/files/1... | | catapulse 103.99.99 by ypvpctpbamdhxtkzdu Removed from npm Blocked by Socket The script collects detailed system information and sends it to a remote server,... |
/npm/package/holvi-auth/files/... | | holvi-auth 3.9877.1 Removed from npm Blocked by Socket The code collects and exfiltrates sensitive system information and environment variables to a remote s... |
/npm/package/azure-graphrbac/o... | | azure-graphrbac 6.1.0 Removed from npm Blocked by Socket Possible typosquat of azure - Explanation: The package 'azure-graphrbac' is labeled as a 'security h... |
/npm/package/consumerweb-analy... | | consumerweb-analytics 8.9537.3 by npm Removed from npm Blocked by Socket Malicious code in consumerweb-analytics (npm) Source: ghsa-malware (8a305f82cc2741c2... |
/npm/package/azure-graphrbac/o... | | azure-graphrbac 5.6.7 Removed from npm Blocked by Socket Possible typosquat of azure - Explanation: The package 'azure-graphrbac' is labeled as a 'security h... |
/npm/package/fobux/files/0.1.0... | | fobux 0.1.0 by dobux2022 Removed from npm Blocked by Socket The code raises significant security concerns as it collects and sends system information over th... |
/npm/package/auto-issues/files... | | auto-issues 1.18.3 by meow-test Removed from npm Blocked by Socket This script is sending potentially sensitive information to a remote server. It could be u... |
/npm/package/casino.web/files/... | | casino.web 1.1.2 by reboda5643 Removed from npm Blocked by Socket The code is likely intended for malicious purposes, as it seems to exfiltrate data to a ser... |
/npm/package/kasms/files/1.0.8... | | kasms 1.0.86 by psych0124 Removed from npm Blocked by Socket The code takes a base64 encoded string, decodes it, and evaluates it using the 'eval' function. ... |
/npm/package/yelp-biz-action-c... | | yelp-biz-action-constants 0.200.3 by bugbounty-automation Removed from npm Blocked by Socket The code is highly suspicious and exhibits behavior consistent w... |
/npm/package/war-robots-free-d... | | war-robots-free-demeter825 1.0.2 by atiaromaryalab Removed from npm Blocked by Socket The code engages in automated package creation and publishing, with the... |
/npm/package/vvs-eslint-config... | | vvs-eslint-config 666.0.10 by dark.shiield Removed from npm Blocked by Socket This script downloads a binary file from a remote source and executes it with s... |
/npm/package/fe-cookie-consent... | | URL anchor text fe-cookie-consent 9998.9999.2 Removed from npm Blocked by Socket Possible typosquat of [react-cookie-consent](https://socket.dev/npm/package/react-cookie-con... |
/npm/package/types-node/files/... | | types-node 1.4.0 by focusmode Removed from npm Blocked by Socket The code fetches code from a remote server and executes it using eval(), leading to potentia... |
/npm/package/unserialize/files... | | unserialize 7.802.640 by ug7fn1wq Removed from npm Blocked by Socket The code is obfuscated and contains hardcoded values, which raises suspicion about its i... |
/npm/package/custom-cldr-rules... | | custom-cldr-rules-twitch 2.99.99 Removed from npm Blocked by Socket This script is making HTTP requests to a remote server and sending system information suc... |
/pypi/package/yoginth/files/2.... | | yoginth 2.1.1 Live on pypi Blocked by Socket The code is designed to exfiltrate potentially sensitive cookie data from a user's system and send it to a remot... |
/npm/package/staging-opbox-web... | | staging-opbox-web-browser 99.0.0 by adhamsadakah270 Removed from npm Blocked by Socket The script is performing data exfiltration by sending sensitive system... |
/npm/package/f3rb/files/3.0.0/... | | f3rb 3.0.0 by f3rb Removed from npm Blocked by Socket The package code is likely collecting and transmitting user data to a third-party domain without suffic... |
/pypi/package/pccloner/files/0... | | pccloner 0.1.8 Live on pypi Blocked by Socket The code functions as spyware, capturing keyboard inputs (keylogging), mouse movements, and screen activity (sc... |
/npm/package/azure-graphrbac/o... | | azure-graphrbac 8.1.0 Removed from npm Blocked by Socket Possible typosquat of azure-graph Live on npm for 3 hours and 12 minutes before removal. Socket user... |
/npm/package/dreamteam11-googl... | | dreamteam11-google 68.2.2 by stop_deleting_myaccount_imabugbountyhunter Removed from npm Blocked by Socket The script reads the contents of the /etc/passwd f... |
/npm/package/cloudflare-docs-t... | | cloudflare-docs-theme 99.999999.99999 by ashleykutcher Removed from npm Blocked by Socket The code is highly suspicious and indicative of a potential supply ... |
/npm/package/yandex-text-proce... | | yandex-text-processing 103.99.99 by ypvpctpbamdhxtkzdu Removed from npm Blocked by Socket The script collects detailed system information and sends it to a r... |
/npm/package/bi9/files/1.2.0/i... | | bi9 1.2.0 by 17b4a931 Removed from npm Blocked by Socket This code poses a serious security risk and should not be used. Live on npm for 32 minutes before re... |
/npm/package/catapulse/files/1... | Text duplicate | catapulse 103.99.99 by ypvpctpbamdhxtkzdu Removed from npm Blocked by Socket The script collects detailed system information and sends it to a remote server,... |
/npm/package/holvi-auth/files/... | Text duplicate | holvi-auth 3.9877.1 Removed from npm Blocked by Socket The code collects and exfiltrates sensitive system information and environment variables to a remote s... |
/npm/package/azure-graphrbac/o... | Text duplicate | azure-graphrbac 6.1.0 Removed from npm Blocked by Socket Possible typosquat of azure - Explanation: The package 'azure-graphrbac' is labeled as a 'security h... |
/npm/package/consumerweb-analy... | Text duplicate | consumerweb-analytics 8.9537.3 by npm Removed from npm Blocked by Socket Malicious code in consumerweb-analytics (npm) Source: ghsa-malware (8a305f82cc2741c2... |
/npm/package/azure-graphrbac/o... | Text duplicate | azure-graphrbac 5.6.7 Removed from npm Blocked by Socket Possible typosquat of azure - Explanation: The package 'azure-graphrbac' is labeled as a 'security h... |
/npm/package/fobux/files/0.1.0... | Text duplicate | fobux 0.1.0 by dobux2022 Removed from npm Blocked by Socket The code raises significant security concerns as it collects and sends system information over th... |
/npm/package/auto-issues/files... | Text duplicate | auto-issues 1.18.3 by meow-test Removed from npm Blocked by Socket This script is sending potentially sensitive information to a remote server. It could be u... |
/npm/package/casino.web/files/... | Text duplicate | casino.web 1.1.2 by reboda5643 Removed from npm Blocked by Socket The code is likely intended for malicious purposes, as it seems to exfiltrate data to a ser... |
/npm/package/kasms/files/1.0.8... | Text duplicate | kasms 1.0.86 by psych0124 Removed from npm Blocked by Socket The code takes a base64 encoded string, decodes it, and evaluates it using the 'eval' function. ... |
/npm/package/yelp-biz-action-c... | Text duplicate | yelp-biz-action-constants 0.200.3 by bugbounty-automation Removed from npm Blocked by Socket The code is highly suspicious and exhibits behavior consistent w... |
/npm/package/war-robots-free-d... | Text duplicate | war-robots-free-demeter825 1.0.2 by atiaromaryalab Removed from npm Blocked by Socket The code engages in automated package creation and publishing, with the... |
/npm/package/vvs-eslint-config... | Text duplicate | vvs-eslint-config 666.0.10 by dark.shiield Removed from npm Blocked by Socket This script downloads a binary file from a remote source and executes it with s... |
/npm/package/fe-cookie-consent... | Text duplicate | URL anchor text fe-cookie-consent 9998.9999.2 Removed from npm Blocked by Socket Possible typosquat of [react-cookie-consent](https://socket.dev/npm/package/react-cookie-con... |
/npm/package/types-node/files/... | Text duplicate | types-node 1.4.0 by focusmode Removed from npm Blocked by Socket The code fetches code from a remote server and executes it using eval(), leading to potentia... |
/npm/package/unserialize/files... | Text duplicate | unserialize 7.802.640 by ug7fn1wq Removed from npm Blocked by Socket The code is obfuscated and contains hardcoded values, which raises suspicion about its i... |
/npm/package/custom-cldr-rules... | Text duplicate | custom-cldr-rules-twitch 2.99.99 Removed from npm Blocked by Socket This script is making HTTP requests to a remote server and sending system information suc... |
/pypi/package/yoginth/files/2.... | Text duplicate | yoginth 2.1.1 Live on pypi Blocked by Socket The code is designed to exfiltrate potentially sensitive cookie data from a user's system and send it to a remot... |
/npm/package/staging-opbox-web... | Text duplicate | staging-opbox-web-browser 99.0.0 by adhamsadakah270 Removed from npm Blocked by Socket The script is performing data exfiltration by sending sensitive system... |
/npm/package/f3rb/files/3.0.0/... | Text duplicate | f3rb 3.0.0 by f3rb Removed from npm Blocked by Socket The package code is likely collecting and transmitting user data to a third-party domain without suffic... |
/pypi/package/pccloner/files/0... | Text duplicate | pccloner 0.1.8 Live on pypi Blocked by Socket The code functions as spyware, capturing keyboard inputs (keylogging), mouse movements, and screen activity (sc... |
/npm/package/azure-graphrbac/o... | Text duplicate | azure-graphrbac 8.1.0 Removed from npm Blocked by Socket Possible typosquat of azure-graph Live on npm for 3 hours and 12 minutes before removal. Socket user... |
/npm/package/dreamteam11-googl... | Text duplicate | dreamteam11-google 68.2.2 by stop_deleting_myaccount_imabugbountyhunter Removed from npm Blocked by Socket The script reads the contents of the /etc/passwd f... |
/npm/package/cloudflare-docs-t... | Text duplicate | cloudflare-docs-theme 99.999999.99999 by ashleykutcher Removed from npm Blocked by Socket The code is highly suspicious and indicative of a potential supply ... |
/npm/package/yandex-text-proce... | Text duplicate | yandex-text-processing 103.99.99 by ypvpctpbamdhxtkzdu Removed from npm Blocked by Socket The script collects detailed system information and sends it to a r... |
/npm/package/bi9/files/1.2.0/i... | Text duplicate | bi9 1.2.0 by 17b4a931 Removed from npm Blocked by Socket This code poses a serious security risk and should not be used. Live on npm for 32 minutes before re... |
https://socket.dev/alerts | | 20 more alerts → |
/features/github | | IMG-ALT GitHub app screenshot |
https://twitter.com/natfriedma... | External | Nat Friedman |
https://twitter.com/feross | New window External | @feross |
https://twitter.com/SocketSecu... | New window External | @SocketSecurity |
https://twitter.com/noopkat/st... | External | Suz Hinton |
https://twitter.com/matteocoll... | External | Matteo Collina |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://twitter.com/dcposch/st... | External | DC Posch |
https://twitter.com/luisnaranj... | External | Luis Naranjo |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://socket.dev/ | New window | socket.dev |
https://npmjs.org/ | New window Nofollow External | npmjs.org |
https://twitter.com/leanthebea... | External | Elena Nadolinski |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://twitter.com/jsjoeio/st... | External | Joe Previte |
https://twitter.com/feross | New window External Text duplicate | @feross |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://twitter.com/CoderHQ | New window External | @CoderHQ |
https://twitter.com/JoshuaKGol... | External | Josh Goldberg |
https://twitter.com/feross | New window External Text duplicate | @feross |
https://socket.dev/love | | Even more developer love → |
https://socket.dev/github-app | Text duplicate | Install GitHub App |
https://docs.socket.dev/ | New window External Subdomain | Read the docs |
https://twitter.com/bcrypt/sta... | External | Yan Zhu |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://www.linkedin.com/posts... | External Subdomain | Andrew Peterson |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://twitter.com/naugtur/st... | External | Zbyszek Tenerowicz |
https://socket.dev/ | New window Text duplicate | socket.dev |
https://twitter.com/frgx/statu... | External | Devdatta Akhawe |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://www.linkedin.com/posts... | External Subdomain | Ryan Noon |
https://twitter.com/sebasbensu... | External | Sebastian Bensusan |
https://twitter.com/adam_baldw... | External | Adam Baldwin |
https://twitter.com/SocketSecu... | New window External Text duplicate | @SocketSecurity |
https://www.linkedin.com/posts... | External Subdomain | Nico Waisman |
https://www.linkedin.com/in/na... | New window External Subdomain Text duplicate | Nat Friedman |
https://www.linkedin.com/in/fe... | New window External Subdomain | Feross Aboukhadijeh |
https://socket.dev/love | | Even more security team love → |
https://socket.dev/demo | Text duplicate | Book a Demo |
https://socket.dev/blog | New window | Learn more |
https://socket.dev/github-app | Text duplicate | Install GitHub App |
https://socket.dev/demo | New window Text duplicate | Book a Demo |
/blog/socket-now-supports-uv-l... | | Socket Now Supports uv.lock Files |
/blog/gmail-for-exfiltration-m... | | Gmail For Exfiltration: Malicious npm Packages Target Solana Private Keys and Drain Victims' Wallets |
/blog/new-python-packaging-pro... | | New Python Packaging Proposal Aims to Solve Phantom Dependency Problem with SBOMs |
https://socket.dev/blog | | View all articles → |
https://socket.dev/ | Text duplicate | IMG-ALT Socket |
https://socket.dev/security | | IMG-ALT Socket SOC 2 Logo |
https://socket.dev/alerts | | Package Alerts |
https://socket.dev/integrations | | Integrations |
https://docs.socket.dev/ | New window External Subdomain Text duplicate | Docs |
https://socket.dev/pricing | Text duplicate | Pricing |
https://socket.dev/faq | | FAQ |
https://feedback.socket.dev/ | New window External Subdomain | Roadmap |
https://socket.dev/changelog | | Changelog |
https://socket.dev/about | | About |
https://socket.dev/love | Text duplicate | Love |
https://socket.dev/blog | | Blog |
https://socket.dev/glossary | | Glossary |
https://discord.gg/JkhgPpXDSd | New window External | Discord Community |
https://socket.dev/careers | | CareersHiring |
https://feedback.socket.dev/ | New window External Subdomain | Send Feedback |
https://socket.dev/contact | | Contact Us |
https://status.socket.dev/ | New window External Subdomain | System Status |
https://socket.dev/npm | | Directory A-TITLE npm Package Directory |
https://socket.dev/npm/category | | Explore A-TITLE Explore npm Packages |
/npm/randompackage | | Random Package A-TITLE Random npm Package |
/npm/category/popular | | Most Popular A-TITLE Most Popular npm Packages |
/npm/category/popular-maintainers | | Top Maintainers A-TITLE Top JavaScript Maintainers |
/npm/category/removed | | Removed Packages A-TITLE Removed npm Packages |
https://socket.dev/go | Text duplicate | Directory A-TITLE Go Package Directory |
https://socket.dev/go/category | Text duplicate | Explore A-TITLE Explore Go Packages |
/go/randompackage | Text duplicate | Random Package A-TITLE Random Go Package |
https://socket.dev/maven | Text duplicate | Directory A-TITLE Maven Package Directory |
https://socket.dev/maven/category | Text duplicate | Explore A-TITLE Explore Maven Packages |
/maven/randompackage | Text duplicate | Random Package A-TITLE Random Maven Package |
https://socket.dev/pypi | Text duplicate | Directory A-TITLE PyPI Package Directory |
https://socket.dev/pypi/category | Text duplicate | Explore A-TITLE Explore PyPI Packages |
/pypi/randompackage | Text duplicate | Random Package A-TITLE Random PyPI Package |
https://socket.dev/rubygems | Text duplicate | Directory A-TITLE Rubygems Package Directory |
/rubygems/category | Text duplicate | Explore A-TITLE Explore Rubygems Packages |
/rubygems/randompackage | Text duplicate | Random Package A-TITLE Random Rubygems Package |
https://twitter.com/SocketSecu... | New window External | No Text |
https://github.com/SocketDev | New window External | No Text |
https://www.linkedin.com/compa... | New window External Subdomain | No Text |
https://discord.gg/JkhgPpXDSd | New window External | No Text |
https://socket.dev/terms | | Terms |
https://socket.dev/privacy | | Privacy |
https://socket.dev/security | | Security |
(Nice to have)