> Markdown version of [/events/world-congress-2025/sessions/510-code-red-when-your](https://www.wearedevelopers.com/events/world-congress-2025/sessions/510-code-red-when-your). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Code Red: When Your Tools Turn Against You - **Date:** Thursday, Jul 10, 2025 - **Time:** 10:30–12:30 (120 min) - **Room:** M7 (18 Seats) - **Event:** World Congress 2025 ## Description Did you ever wonder what typosquatting, dependency confusion, malicious maintainers, or shadow libraries really mean, and how they could compromise your applications without a single line of your own code being wrong? Welcome to the hidden war zone of modern software development: the software supply chain. In this workshop, we’ll demystify the most dangerous and fast-evolving attack vectors that are targeting developers through the tools they trust, package managers, build systems, third-party libraries, and CI/CD pipelines. Through real-world case studies and code-level examples, we’ll unpack how: Attackers exploit developer mistakes with typosquatting. Internal dependencies are hijacked via dependency confusion. Maintainers or compromised packages introduce malware into trusted ecosystems. Obscure transitive dependencies become silent backdoors. This session is designed for developers who want to understand the risks, recognize the signs, and start building defense-in-depth strategies. If time permits, we’ll get hands-on with practical exercises where you’ll see (and maybe try) some of these attack techniques in a controlled environment—so you can learn how to defend against them in the wild. Come prepared to rethink your assumptions about open source and start building a more resilient development workflow. ## Speakers ### [Aaron Bray](https://www.wearedevelopers.com/@aaron-bray) Director of Product Management at Veracode ### [Julian Totzek-Hallhuber](https://www.wearedevelopers.com/@julian-totzek-hallhuber) Veracode, Manager Solution Architects EMEA & APAC ## Related talks at this congress - [Supply Chain Security and the Real World: Lessons From Incidents](https://www.wearedevelopers.com/events/world-congress-2025/sessions/685-supply-chain) — Adrian Mouat - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/events/world-congress-2025/sessions/860-real-world-security) — Kevin Lewis - [How GitHub secures open source](https://www.wearedevelopers.com/events/world-congress-2025/sessions/670-how-github-secures) — Joseph Katsioloudes - [Friend or Foe? TypeScript Security Fallacies](https://www.wearedevelopers.com/events/world-congress-2025/sessions/694-friend-or-foe) — Liran Tal