Socket Threat Feed API
Real-time feed of newly discovered malicious or suspicious packages across npm, PyPI, Go, RubyGems, and other ecosystems. Filter by ecosystem, alert type, and time window. Powers Socket's malware research dashboards and the public-disclosure firehose.
Socket Threat Feed API is one of 15 APIs that Socket publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
This API exposes 1 machine-runnable capability that can be deployed as REST, MCP, or Agent Skill surfaces via Naftiko.
Tagged areas include Threat Feed, Malware, and Real-Time Intelligence. The published artifact set on APIs.io includes API documentation, an OpenAPI specification, and 1 Naftiko capability spec.