> Markdown version of [/videos/2138-wearedevelopers-live-node-and-package-security?t=2619](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security?t=2619). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # WeAreDevelopers LIVE - Node and Package Security Are malicious post-install scripts threatening your JavaScript projects? Stop attackers in their tracks. Learn how to neutralize supply chain vulnerabilities using LavaMoat Harden and strict node permissions. - **Speakers:** [Chris Heilmann](https://www.wearedevelopers.com/@chris-heilmann), [Daniel Cranney](https://www.wearedevelopers.com/@daniel-cranney), Zbyszek Tenerowicz - **Event:** WeAreDevelopers LIVE - **Published:** August 5, 2026 - **Duration:** 1:08:30 - **URL:** https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security ## Summary The conversation opens with an exploration of current tech events, focusing on new EU regulations mandating the labeling of deepfakes and automated content. The hosts discuss how such regulations often act as a social contract or taboo rather than perfectly enforceable laws. This leads into a broader critique of generated articles and the degradation of trust in online platforms, capturing the sentiment perfectly with the quote, "Why should I bother reading something you didn't bother to write?" The dialogue also touches on the frustration of malicious compliance in cookie consent banners, noting that many sites leak user data to ad-tech partners before consent is even granted. Shifting toward developer tools and security concepts, the hosts highlight several fascinating community projects, including an IKEA complexity index, a tool for undoing destructive Unix commands, and a leaderboard tracking quantum computing improvements for cracking passwords. After a lighthearted Fake or News segment that underscores the absurdity of modern tech headlines, the episode transitions into a deep dive on open-source supply chain security within the JavaScript ecosystem. The core technical focus centers on securing node package managers against malicious dependencies. With attackers increasingly exploiting post-install scripts, modern tools like npm, pnpm, and Yarn have introduced breaking but necessary security enhancements. The discussion highlights LavaMoat Harden, an open-source tool that automates optimal security configurations for package managers. By enabling staged trusted publishing and utilizing node permissions to restrict script execution environments—such as enforcing read-only disk access and offline execution for linters—developers can effectively neutralize entire classes of supply chain vulnerabilities before they compromise a system. **Keywords:** npm supply chain security, lavamoat harden configuration, javascript package managers, post-install script vulnerabilities, staged trusted publishing, node execution permissions, deepfake content regulations, automated content labeling, cookie consent tracking, quantum password cracking, open-source dependency risks, malicious privacy compliance, unix command recovery, pnpm security configurations, yarn script permissions ## Chapters 1. **Defining the product marketing manager role in tech** (00:00) — How product marketing aligns external audience perception with internal company goals. 1. **Viability of open-source mobile operating systems** (03:33) — The challenges of building alternatives to mainstream mobile platforms and adapting to modular hardware. 1. **Regulating deepfake content and AI transparency in Europe** (09:44) — How the European Union enforces labels on AI-generated content to protect digital identities. 1. **Balancing AI automation with human curation in content creation** (18:07) — Strategies for utilizing AI to draft content while maintaining quality and authentic human intent. 1. **Eliminating cookie banners through browser-level privacy settings** (24:45) — How European regulations aim to replace disruptive cookie banners with standardized browser consent. 1. **Preventing web scraping using ligature-based typography tricks** (31:38) — The accessibility trade-offs of hiding text from AI scrapers using visual font overlays. 1. **Exploring community-built data analysis tools and visualizations** (33:16) — A look at creative side projects like Wikipedia image searchers and the IKEA complexity index. 1. **Measuring password vulnerability against future quantum computing threats** (37:35) — How cryptographic researchers compete to optimize algorithms for quantum-based password cracking. 1. **Reverting destructive Unix commands with the Undo utility** (43:39) — How the Undo tool leverages shell hooks to recover from accidental command-line deletions. 1. **Testing technology knowledge with a tech news trivia game** (45:21) — A trivia segment challenging guests to identify real versus fabricated software and technology headlines. 1. **Securing package managers using the Lavamoat Harden project** (51:01) — Automating package manager configuration to mitigate supply chain attacks and malicious installation scripts. 1. **Automating staged publishing for secure package releases** (55:17) — Using custom bookmarklets to streamline two-factor authentication and staged publishing workflows on npm. 1. **Limiting script execution permissions in Node and package managers** (58:56) — Restricting disk and network access for package scripts to prevent unauthorized data exfiltration. ## Related Moments - [Audience questions on tool configurations and package locks](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) (from "Oops! Stories of supply chain shenanigans") - [Addressing audience concerns on licensing and privacy](https://www.wearedevelopers.com/videos/522-how-we-will-build-the-software-of-tomorrow) (from "How we will build the software of tomorrow") - [Bridging the gap between developers and security tools](https://www.wearedevelopers.com/videos/1829-how-to-defend-against-data-manipulation-attacks-bozidar-spirovski-wekoslav-stefanovski) (from "How to Defend Against Data Manipulation Attacks - Bozidar Spirovski & Wekoslav Stefanovski") - [Exploring advanced security tooling and community dependency vetting](https://www.wearedevelopers.com/videos/1041-reviewing-3rd-party-library-security-easily-using-openssf-scorecard) (from "Reviewing 3rd party library security easily using OpenSSF Scorecard") - [Audience questions on model security and continuous fuzzing](https://www.wearedevelopers.com/videos/347-mlops-and-ai-driven-development) (from "MLOps and AI Driven Development") - [Dependency risks in widespread NPM supply chain attacks](https://www.wearedevelopers.com/videos/1719-wearedevelopers-live-fun-and-games-and-all-that-comes-with-it-back-to-basic-more) (from "WeAreDevelopers LIVE - "Fun and games - and all that comes with it", Back to BASIC & more") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Senior Software Engineer](https://www.wearedevelopers.com/jobs/ext/15942-senior-software-engineer) at **GitHub** - [Principal Product Manager, Agent Platform](https://www.wearedevelopers.com/jobs/ext/277541-principal-product-manager-agent-platform) at **GitHub** - [Staff Engineer - Offensive Security](https://www.wearedevelopers.com/jobs/ext/1226927-staff-engineer-offensive-security) at **Twilio** - [Senior Engineer, Infrastructure Platform](https://www.wearedevelopers.com/jobs/ext/328836-senior-engineer-infrastructure-platform) at **Intercom, Inc.**