About this talk
This talk, presented by Sudhanshu Dasgupta and Sahil Bansal from SafeDep, delves into the Shai-Hulud supply chain worm, which compromised over 500 npm packages and executed credential theft, repository hijacking, and self-replication within seconds. The session highlights the limitations of traditional static analysis in detecting zero-day supply chain attacks and discusses the importance of dynamic runtime monitoring in sandboxed containers. The speakers also explain how Falco and eBPF-based behavioral detection rules can identify malicious package behavior during installation, allowing for proactive classification before any damage occurs.
More from this event
See all 28 talks →
Ai, Deception And Deepfakes When Trust Becomes The Primary Attack Surface
36:15
Cloud Resilience Simplified Less Data, Stronger Security
33:14
Demystifying Driver Research A Systematic Approach For Vulnerability Hunting
25:24
Dpdpa In Action Designing A 72 Hour Breach Response That Actually Works
22:56