Software supply chain security platform detecting malware in open source dependencies
Socket detects and prevents malware in open source code by analyzing package dependencies at scale. The tech stack—JavaScript, TypeScript, Python, Go, Rust across GitHub Actions, Jenkins, CircleCI—reflects a multi-language vulnerability scanning engine, while real-time analytics (Kafka, NATS, RabbitMQ, ClickHouse, BigQuery) and fraud detection prototypes suggest they're moving beyond static SCA toward behavioral threat detection. Hiring velocity is decelerating but skews senior (10 of 19 roles), indicating a shift from growth hiring toward product depth and enterprise implementation.
Socket is a supply chain security platform protecting engineering teams from malware and vulnerabilities in open source dependencies. The company's product combines software composition analysis (SCA), SBOM generation, and zero-day prevention. Work centers on three areas: detection and analysis (building SAST rules, CVE models, and fraud detection), customer onboarding (playbooks and professional services), and enterprise adoption (API development, custom integrations). Founded in 2020 and based in San Francisco, Socket operates with 51–200 employees and is actively hiring across engineering, sales, and support in the US and Bulgaria.
Socket's analysis engine runs across JavaScript, TypeScript, Python, Go, and Rust. The platform integrates with npm, yarn, pnpm for package management and GitHub, GitLab, Bitbucket for code repositories.
Active projects include real-time analytics pipelines, fraud detection prototypes, custom SAST rule development, API tooling for data integration, and professional services implementation for enterprise customers.
Other companies in the same industry, closest in size