It Works on My Box: Compromising Developers via Package Registry Malware


Posted on in Presentations

Supply chain attacks against public registries are an emerging initial access vector. This talk will share our findings from systematically scanning millions of packages across package registries for malware and reveal what is behind supply chain malware, the criminal ecosystem behind this vector, and how nation-states are now abusing this vector for breaching companies.

Access This and Other RSAC Conference Presentations with Your Free RSAC Membership

Your RSAC Membership also includes AI-powered summaries, mind maps, and slides for Conference presentations, Group Discussions with experts, and more.

Watch Now >>
Participants
Zack Allen

Speaker

Senior Director, Datadoghq

Ian Kretz

Speaker

Security Researcher, Datadog


Share With Your Community