About this talk
This talk explores the oversight of the NPM ecosystem regarding malicious packages and security threats. The speaker, Paul McCarty, discusses the use of innovative canary tokens, referred to as "canary packages," strategically placed in published packages to monitor the effectiveness of security vendors' detection capabilities, identify blind spots, and analyze scanning behaviors. This research sheds light on the current security landscape of the NPM ecosystem and the proactive measures that are necessary to enhance package safety.
More from this event
See all 91 talks →
BSidesSF 2026 - Opening Remarks (Sunday) (Reed Loden)
14:36
BSidesSF 2026 - Follow the data to learn the secret (Dylan Ayrey)
35:17
BSidesSF 2026 - Not My Vibe: When AI Coding Agents Go Off the Rails (Aonan Guan, Zhengyu Liu)
45:56
BSidesSF 2026 - "Ask the EFF" Panel (Panel)
45:30