Dependency Confusion As A Tool For Targeted NPM Hacks episode artwork

EPISODE · Sep 8, 2022 · 42 MIN

Dependency Confusion As A Tool For Targeted NPM Hacks

from ConversingLabs Podcast · host ReversingLabs

NPM dependency confusion has emerged as a potent software supply chain attack vector via platforms like npm, with malicious packages surreptitiously added to these repositories, maintained by leading firms. In this episode, we're joined by ReversingLabs Reverse Engineer Karlo Zanki to dig into some of our recent findings that show dependency confusion attacks are being used to advance what appear to be targeted supply chain attacks. We will also talk about how development organizations can monitor for and prevent these kinds of attacks. 

Episode metadata supplied by the publisher feed · Published Sep 8, 2022

Embed this episode

We chatted with ReversingLabs Reverse Engineer Karlo Zanki about how NPM packages have been caught serving malware via compromised software updates.

Distinct summary based on available episode metadata or transcript content.

Ready to play

Dependency Confusion As A Tool For Targeted NPM Hacks

0:00 42:20

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of ConversingLabs Podcast?

This episode is 42 minutes long.

When was this ConversingLabs Podcast episode published?

This episode was published on September 8, 2022.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this ConversingLabs Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!