NY State-Licensed Certificates in Design, Coding & AI — Online
Learn Backend Development Part-Time, Online
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
The talk examines how attackers exploit trust in package managers and presents a large-scale system for vetting software packages for malware and other risky attributes. It also introduces a tool that helps developers audit dependencies and receive alerts when they turn malicious.
Syllabus
Intro
Open-source software is eating the world
Package managers
Bad actors exploit this trust
Software supply chain attack
Attack Technique: Typosquatting
Case study: mitmpraxy2
Technique: Social Engineering
Technique: Dependency Confusion
Technique: Account Hijacking
How to defend against these attacks
Manual vetting is infeasible
Existing tools report KNOWN CVES
Vanity stats are not enough
Packj: a dev-friendly vetting tool
API Analysis
Metadata Analysis
Enabling package vetting at scale
Taught by
PyCon US