
Poisoned Packages & Stolen Secrets: The Rise of Supply Chain Attacks
Source: YouTube · SANS Digital Forensics and Incident Response · published Jun 26, 2026 · 1:00:23
Malicious software supply chain attacks are exploding, but while noisy threat actors like Team PCP grab headlines, the real danger comes from state-sponsored groups like DPRK (North Korea) who are quietly, efficiently, and automatically compromising thousands of developers at scale 1:34.
Key Takeaways:
• Team PCP is highly publicized but likely just 1-3 individuals; they copied techniques from the original Shai Hulud worm and shouldn't be conflated with it, as they lack the scale and financial impact of nation-state actors 6:09.
• NPM hosts 98.5% of all malicious packages, and JavaScript's massive dependency footprint (averaging 1,100+ transitive dependencies per project) creates an exponentially larger attack surface than any other language 12:17.
• DPRK's "Contagious Interview" evolved into the automated "Pollen Writer" campaign, using developer persistence to spread laterally across GitHub, compromising tens of thousands of developers—growing over 1,400% this year alone 23:13.
• EDR solutions consistently miss these attacks because they fail to detect interpreted payloads (JavaScript/Python), developers often bypass EDR entirely, and info-stealers now target password managers, AI keys, and even leverage Claude skills 34:25.
• Defenders should use dedicated threat feeds like OSM, enable SCM audit logs, implement SBOMs, and prioritize blocking malicious packages on developer laptops—stopping the poison before it enters the water supply 52:17.
Defenders must shift focus from headline-grabbing threat actors to the quiet, automated campaigns that are actively poisoning the software supply chain at an unprecedented scale.
Sources:
- 1:34 Introduction to the exploding threat of malicious software supply chain attacks
- 6:09 Breakdown of Team PCP vs. original Shai Hulud and threat actor conflation
- 12:17 NPM dominance in malicious packages and JavaScript's dependency bloat
- 23:13 DPRK's evolution from Contagious Interview to automated Pollen Writer campaign
- 34:25 Why EDR fails to detect interpreted payloads and new info-stealer targets
- 52:17 Defender recommendations including OSM feeds, SBOMs, and the water supply metaphor
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[music] [music] [music] >> Hey everyone, welcome one, welcome all, welcome back to the SANS Threat Analysis Rundown livestream. I'm Shaun O'Connor and if anyone is joining for the first time, STAR is a monthly livestream built for defenders, no vendor pitches, no recycled headlines, uh just kind of combos about what's going on in the threat landscape and kind of what defenders can do about it. Uh so this month we're getting into something that has just exploded not just in the last year, but really especially in the last like, you know, three to five months and that's malicious software supply chain attacks. And so threat actors are going after trusted packages, uh you know, you know, repos, CICD workflows that devs rely on every single day. And so to break all this down, I've got exactly …