World Congress 2026 North America

Silent Execution: Defending Against Install-Time Supply Chain Attacks

September 25, 2026 16:15 – 16:25 · 10 min Outdoor Stage

World Congress 2026 North America

September 23–25, 2026 · San José, CA

Attend in person

Get tickets

Watch remotely

Watch live with Pro

Pro

Can’t make it to San José? Watch this session live with Pro. You also get:

  • All full videos, bookmarks, and playlists
  • World Congress livestreams
See pricing

What this session covers

While we often focus on securing the React Native bridge or runtime data, the most immediate threat to your project might execute before you even hit “build.” In early 2026, the “Glassworm” attacks proved that a developer’s environment can be compromised in seconds through malicious npm lifecycle scripts that exfiltrate credentials during a standard installation. This 15-minute technical deep dive breaks down the mechanics of install-time malware, analyzes why standard audit tools often miss these exploits, and provides a concrete roadmap for hardening your local environment and CI/CD pipelines using script-blocking strategies and behavioral monitoring.

Related talks at this congress

Open session

World Congress 2026 North America

September 25, 2026 · 09:40–10:10

Stage 4

Your registry can't stop a valid login. What happens then?

Khushboo Verma

Systems Engineer at Cloudflare

Khushboo Verma
Open session

World Congress 2026 North America

September 23, 2026 · 14:00–14:30

Stage 1

Supply Chain Security When Agents Write the Code

Ajeet Raina

Developer Advocate at Docker

Ajeet Raina
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 3

Stop Running Mystery Meat in Production

Jeroen van Erp

Technology Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

September 25, 2026 · 15:00–17:00

Stage 12

Secure development from pull request to production with GitHub

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen
All sessions at this congress