Podcast Episodes
Back to Search
Supply Chain Is More Than Just Dependencies
Season 1 Episode 4
Most developers think software supply chain security starts and ends with dependencies. But modern supply chain attacks don't stop there. Attackers l…
8 hours ago
Malicious Dependencies Aren’t an Accident
Season 1 Episode 3
Malicious dependencies are not accidents. They are often intentionally designed to look trustworthy so developers install them without hesitation. In…
2 weeks, 1 day ago
NPM Supply Chain Attack: Active Worm Stealing Tokens, SSH Keys, and Credentials
Season 1
🚨 Emergency DevSec Station update.
There’s an active npm supply chain attack happening right now.
Malicious npm packages are running install scripts th…
1 month, 1 week ago
How Modern Supply Chain Attacks Really Happen (Step-by-Step Breakdown for Developers)
Season 1 Episode 2
What if a supply chain attack didn’t start with a complex exploit… but something completely normal?
A typo.
A copy-paste.
Even an AI suggestion.
In thi…
1 month, 3 weeks ago
Developers Are Now Targets: How Supply Chain Attacks Actually Reach You
Season 1 Episode 1
Developers are no longer just building software.
They’re being targeted directly.
In this episode, Tanya Janca explains how supply chain attacks reach…
2 months, 2 weeks ago