> Markdown version of [/videos/100558-silent-execution-defending-against-install-time-supply-chain-attacks](https://www.wearedevelopers.com/videos/100558-silent-execution-defending-against-install-time-supply-chain-attacks). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Silent Execution: Defending Against Install-Time Supply Chain Attacks Are your npm install scripts silently stealing your GitHub tokens? Discover how malware like Glassworm exploits standard package managers and learn to harden your pipelines against install-time attacks. - **Speakers:** [Chris DeMars](https://www.wearedevelopers.com/@chris-demars) - **Event:** World Congress 2026 North America - **Published:** September 26, 2026 - **Duration:** 11:36 - **URL:** https://www.wearedevelopers.com/videos/100558-silent-execution-defending-against-install-time-supply-chain-attacks ## Access Playback and chapters for this video are available with a Free account. ## Related Moments - [Managing risks in CI/CD pipelines and supply chains](https://www.wearedevelopers.com/videos/100592-coffee-with-developers-with-noris-buriac-forward-security) (from "Coffee with Developers with Noris Buriac (Forward Security)") - [Mitigating supply chain attacks via automated post-install hooks](https://www.wearedevelopers.com/videos/1822-wearedevelopers-live-11ty-and-a11y) (from "WeAreDevelopers LIVE - 11ty and a11y") - [Dependency risks in widespread NPM supply chain attacks](https://www.wearedevelopers.com/videos/1719-wearedevelopers-live-fun-and-games-and-all-that-comes-with-it-back-to-basic-more) (from "WeAreDevelopers LIVE - "Fun and games - and all that comes with it", Back to BASIC & more") - [Evolving attacks from npm scripts to prompt injection](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) (from "The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most") - [Supply chain security risks in NPM dependency code](https://www.wearedevelopers.com/videos/1028-cross-site-scripting-is-yesterday-s-news-isn-t-it) (from "Cross Site Scripting is yesterday's news, isn't it?") - [Highlighting supply chain vulnerabilities from obfuscated package manager backdoors](https://www.wearedevelopers.com/videos/1284-dev-digest-end-of-year-recap) (from "Dev Digest End of Year Recap") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 179: rm -rf, Agent Style, NPM hacks & Browser Design Tools](https://www.wearedevelopers.com/magazine/611-dev-digest-179-rm-rf-agent-style-npm-hacks-browser-design-tools) ## Related Jobs - [Senior Supply Chain Security Engineer](https://www.wearedevelopers.com/jobs/48462-senior-supply-chain-security-engineer) at **Docker, Inc.** - [Senior Principal Software Engineer, Docker and Ecosystem](https://www.wearedevelopers.com/jobs/48456-senior-principal-software-engineer-docker-and-ecosystem) at **Docker, Inc.** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/2628442-staff-developer-advocate-github-security-lab) at **GitHub** - [Principal Software Engineer, Docker Hardened Images](https://www.wearedevelopers.com/jobs/48453-principal-software-engineer-docker-hardened-images) at **Docker, Inc.** - [Senior Software Engineer, Sandboxes (Eu Or East Coast Preferred)](https://www.wearedevelopers.com/jobs/ext/2161904-senior-software-engineer-sandboxes-eu-or-east-coast-preferred) at **Docker, Inc.** - [Senior Software Engineer, Secure Build](https://www.wearedevelopers.com/jobs/48461-senior-software-engineer-secure-build) at **Docker, Inc.**