Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.
- Feross Aboukhadijeh
This week our Threat Research team tracked an active supply chain attack that took over a maintainer account and used it to push malware across the widely used keyv and cacheable packages, then spread to other maintainers through stolen npm tokens. Those packages sit deep in dependency trees and account for tens of millions of weekly downloads.
Attacks like this are getting more frequent, and open source maintainers are the ones on the receiving end. When an account takeover happens, the maintainer is often the last to find out and the first to deal with the fallout, usually alone. And usually for software they maintain for free.
Maintaining critical software now comes with a security burden that has outgrown what any volunteer can reasonably carry. Earlier this year a coordinated social engineering campaign hunted high-impact Node.js maintainers, going after the people behind some of the most depended-on packages in npm. Several Socket engineers were targeted in it, including me. Maintainers are now targets for AI-driven attacks too, from agents that social-engineer their way toward a malicious merge to agents that patiently build a real contribution history to earn a maintainer's trust. AI keeps lowering the barrier to this kind of activity, while maintainers stand as the last human gatekeepers in the supply chain.
Socket is built by open source maintainers. Our team's software is downloaded over a billion times a month, and we know the work and the exposure that come with it. We want to do more.
Free Business plan for open source projects
Since 2024 we have offered open source projects a free upgrade to our Team plan. Starting today we are raising that to a free Business plan.
That gives maintainers Socket's full protection at no cost, including:
- Automatic blocking of malicious dependencies across 80+ risk types
- Reachability analysis
- Scanning for GitHub Actions and AI models, the same CI and agent surfaces attackers are now abusing
- SBOM export, SSO/SAML, and webhook automation
- Unlimited members and repository labels
How to get upgraded
The program is open to any public open source project under a valid OSI license. Sign up for Socket for free, then email support@socket.dev with your GitHub organization name. We will upgrade you to the Business plan and you can start using the additional features right away.
If you already have a free Team upgrade through the program, email the same address and we will move you to Business.
Securing the packages the world depends on should not fall on maintainers alone. This is one way we can carry more of that weight.
