Supply Chain Trust Whole other talk! Key points • Increasingly sophisticated attackers • Target dependencies (libraries, packages, build systems, repositories, etc)
Recent Incidents • • • • • • •
2016 – left-pad (npm) 2017/2018 – Python Package Highjacking (PyPi) 2018 – event-stream (npm) 2019 – Account takeovers of popular packages (Ruby Gems) 2021 – Dependency confusion (all) 2021 – Log4J (maven) 2022 – node-ipc and peacenotwar (npm)