Poisoned Potions: When Code Dependencies Turn Evil episode artwork

EPISODE · Jun 3, 2026 · 17 MIN

Poisoned Potions: When Code Dependencies Turn Evil

from Clown Cast

A deep dive into software supply chain attacks—where a single compromised package can infiltrate thousands of projects through invisible dependency chains. Explore how npm and PyPI became the internet's most dangerous potion shops, from the left-pad collapse to the event-stream backdoor, and the emerging 'slopsquatting' threat where AI hallucinations become actual security vulnerabilities. 00:00 - The Potion Shop Metaphor: How Package Registries Work 02:30 - Dependency Trees: Why You're Installing 1500 Packages Without Knowing It 06:00 - The Left-Pad Incident: When 11 Lines of Code Broke the Internet 09:30 - The Event-Stream Backdoor: A Trojan Horse in Plain Sight 13:00 - Slopsquatting: AI-Generated Package Names as Attack Vectors 17:00 - Defense Strategies: Can You Trust Your Dependencies? This podcast episode was fully generated by AI — research, script, voices, and production. Built with Claude, Piper TTS, and automated pipeline tooling.

Episode metadata supplied by the publisher feed · Published Jun 3, 2026

Embed this episode

NOW PLAYING

Poisoned Potions: When Code Dependencies Turn Evil

0:00 17:38

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Clown Cast?

This episode is 17 minutes long.

When was this Clown Cast episode published?

This episode was published on June 3, 2026.

Can I download this Clown Cast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!