World Congress 2026 North America • Sep 26, 2026 • Session details

Silent Execution: Defending Against Install-Time Supply Chain Attacks

Chris DeMars

Are your npm install scripts silently stealing your GitHub tokens? Discover how malware like Glassworm exploits standard package managers and learn to harden your pipelines against install-time attacks.

Silent Execution: Defending Against Install-Time Supply Chain Attacks thumbnail

Checking access…

Playback and chapters load privately for Free videos.

Matching moments

2:56 min

Managing risks in CI/CD pipelines and supply chains

Christian Heilmann Christian Heilmann +1 · World Congress 2026 North America

3:50 min

Mitigating supply chain attacks via automated post-install hooks

Chris Heilmann Chris Heilmann +2 · LIVE

2:32 min

Dependency risks in widespread NPM supply chain attacks

Chris Heilmann Chris Heilmann +2 · LIVE

1:55 min

Evolving attacks from npm scripts to prompt injection

Marcus Wermuth Marcus Wermuth · World Congress 2026 Europe

1:50 min

Supply chain security risks in NPM dependency code

martinakraus martinakraus · World Congress 2024

1:03 min

Highlighting supply chain vulnerabilities from obfuscated package manager backdoors

Daniel Cranney Daniel Cranney +1 · LIVE

Upcoming sessions on this topic

Open session

Supply Chain Security for the Everyday Engineer

  • Pradumna Saraf

    Kestra Technologies

    Quality Assurance Engineer

Open session

From Profiler to Production: Measuring What Actually Matters in React & React Native

  • Andrei Tazetdinov

    Dynatrace

    React Native Developer

Open session

How We Cut Our API's p99 Latency from Minutes to Under a Second

  • Deepak Agrawal

    Atlassian

    Principal Software Engineer

Open session

Beware of Strangers Bearing Code: Open Source Trust in the Agent Era

  • Vikram Vaswani

    Consultant

Open session

What I Got Wrong Shipping an MCP Server for Live Infrastructure

  • Pritesh Kiri

    Harness

    Developer Relations Engineer

Open session

Autopsy of an Autonomous Incident: When the Agent Made It Worse

  • Navin Pai

    StackGen

    Director of Engineering