Silent Execution: Defending Against Install-Time Supply Chain Attacks
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Are your npm install scripts silently stealing your GitHub tokens? Discover how malware like Glassworm exploits standard package managers and learn to harden your pipelines against install-time attacks.
Checking access…
Playback and chapters load privately for Free videos.
Matching moments
More from World Congress 2026 North America
Related videos
Related articles
BB
Benedikt Bischof
DC
Daniel Cranney
DC
Daniel Cranney
DC
Daniel Cranney
From learning to earning
Jobs that call for the skills explored in this talk.
about 1 month ago
•
Verified
Senior Supply Chain Security Engineer
Docker, Inc.
Expert
Remote
Linux
Kubernetes
about 1 month ago
•
Verified
Senior Principal Software Engineer, Docker and Ecosystem
Docker, Inc.
Seattle, United States
Expert
Remote
Cloud (AWS/Google/Azure)
2 months ago
Staff Developer Advocate, GitHub Security Lab
GitHub
United States
Experienced
$121k–323k
Remote
Git
Github
Databases
about 1 month ago
•
Verified
Principal Software Engineer, Docker Hardened Images
Docker, Inc.
Expert
Remote
Kubernetes
about 2 months ago
Senior Software Engineer, Sandboxes (Eu Or East Coast Preferred)
Docker, Inc.
Madrid, Spain
€94k–155k
Remote
Docker
Adobe InDesign
Virtual Agents
about 1 month ago
•
Verified
Senior Software Engineer, Secure Build
Docker, Inc.
Expert
Remote
Go