World Congress 2026 North America • Sep 26, 2026 • Session details

Silent Execution: Defending Against Install-Time Supply Chain Attacks

Chris DeMars

Are your npm install scripts silently stealing your GitHub tokens? Discover how malware like Glassworm exploits standard package managers and learn to harden your pipelines against install-time attacks.

Silent Execution: Defending Against Install-Time Supply Chain Attacks thumbnail

Checking access…

Playback and chapters load privately for Free videos.

Matching moments

2:56 min

Managing risks in CI/CD pipelines and supply chains

Christian Heilmann Christian Heilmann +1 · World Congress 2026 North America

3:50 min

Mitigating supply chain attacks via automated post-install hooks

Chris Heilmann Chris Heilmann +2 · LIVE

2:32 min

Dependency risks in widespread NPM supply chain attacks

Chris Heilmann Chris Heilmann +2 · LIVE

1:55 min

Evolving attacks from npm scripts to prompt injection

Marcus Wermuth Marcus Wermuth · World Congress 2026 Europe

1:50 min

Supply chain security risks in NPM dependency code

martinakraus martinakraus · World Congress 2024

1:03 min

Highlighting supply chain vulnerabilities from obfuscated package manager backdoors

Daniel Cranney Daniel Cranney +1 · LIVE