Inside the open source malware attack landscape
Open source attacks are showing up in new places – GitHub repos, npm packages, VS Code extensions. Join OpenSourceMalware and Cloudsmith to break down these new attack vectors, and what companies can do to mitigate these more advanced bad actors.
Things you'll learn
- The attack landscape - Jenn walks through what OpenSourceMalware is tracking right now: compromised GitHub repos and packages linked to North Korea, how threat actors are evolving their malware to evade detection, and a growing wave of malicious VS Code extensions hiding in plain sight.
- Ask us anything - Stay for a live AMA with Jenn and Nigel. Bring the question you can't find an answer to – what to prioritize, what to ignore, what your team should change on Monday.
Speakers


Summary
Malicious open source packages keep finding new doors. Compromised GitHub repositories, state-linked npm packages, and attacks leveraging VS Code extensions installed by developers without a second thought – the attack surface keeps expanding, and most teams are trying to figure out how to keep up.
As co-founder of OpenSourceMalware, she runs the community-driven threat intel that companies rely on, watching malicious packages, domains, and infrastructure in real time across npm, GitHub, and beyond. In this session, she joins Cloudsmith’s Head of Developer Relations, Nigel Douglas, to go through what's changed in the last month or two, why it matters, and what to do before it becomes your postmortem. Then the floor is yours: stay for a live AMA and ask what's on your mind.