Things you'll learn
- How the attack worked – from credential compromise to RAT deployment
- The staging techniques that helped the payload avoid early detection
- Defenses you can put in place today, including dependency pinning, age-based package policies, and threat intelligence integration
Speakers

Nigel Douglas
Head of Developer RelationsCloudsmith

Jenn Gile
FounderOpenSourceMalware
Summary
LIVE BRIEFING: This week, axios - the JavaScript HTTP client with over 100 million weekly npm downloads - was compromised in a supply chain attack. A malicious actor used a compromised maintainer account to inject a remote access trojan into two active release branches.
Join our Head of Developer Relations, Nigel Douglas and Founder of OpenSourceMalware, Jenn Gile for a 30-minute live breakdown of the attack and practical steps any engineering team can take to reduce their exposure to this type of threat.