Skip to content

Socket

2 viewers · 30d

Total raised

$59.4M

+$59.4M this year

1 filing since 2026 · latest Equity filed

Cumulative raised
LAST ROUND
Equity · $59.4M
ROUNDS
1
INVESTORS
8
FOUNDED
N/A
HQ
Wilmington, DE
SECTOR
Cybersecurity
EMPLOYEES
N/A
30D VIEWERS
2

AI overview

Updated

Socket is a developer-first security company that protects applications from software supply chain attacks originating in open source dependencies. Its platform monitors package registries in real time and uses AI-assisted code analysis to detect malware, backdoors, obfuscated code, and data-exfiltration behavior in npm, PyPI, and Go packages, often within minutes of publication. It also flags known vulnerabilities and open source license compliance issues inside existing developer workflows such as pull requests. The company was founded in 2020 by open source maintainer and former Stanford web security lecturer Feross Aboukhadijeh, and has raised roughly $125M across seed, Series A, and Series B rounds from investors including Andreessen Horowitz, Abstract Ventures, Elad Gil, and Thrive Capital.

What sets it apart

Rather than only matching dependencies against a known-vulnerability database, Socket inspects package behavior to catch actively malicious and zero-day supply chain attacks — the company reports detecting over 100 such attacks per week — while keeping false positives low enough for engineers to leave it enabled in their day-to-day workflow.

Funding history

1 round
Equity+2Mar 19, 2026
Form D
+$59.4M$59.4M total

Latest SEC filings

via EDGAR · CIK 0002127421
Form D · Mar 19, 2026View on EDGAR

Products

1 tracked

Socket

Application and software supply chain security platform

A security platform that scans an organization's open source dependencies in real time, blocking malicious packages and surfacing vulnerable or non-compliant ones before they reach production.

  • Real-time monitoring of open source packages for malware, backdoors, and obfuscated code
  • Detection of data-exfiltration and other suspicious behavior in dependency updates
  • AI-powered summaries and triage of detected issues
  • Known-vulnerability scanning and open source license compliance checks