Inside npm Malware Attacks: Protecting Your Software Supply Chain

Inside the npm Malware Attacks: How to Protect Your Software Supply Chain

In the last month, we've witnessed multiple equally sophisticated supply chain attacks; first the npm chalk/debug compromise, followed by Shai Hulud and now a new wave of CanisterWorm. One thing is unmistakably clear: this isn’t going away.

We know you’ve been managing through this. Your CISOs are concerned, and for good reason. Reactive security and SCA tools alone aren’t enough anymore. Once malicious code reaches your environment, it’s already too late.

Join Sonatype’s Roger Lau to see how Nexus Repository Firewall helps you stay ahead of the next breach, by blocking malicious and vulnerable components directly at your repositories, before they ever reach your developers or your AI coding agents.

Featured Speaker

Roger Lau

APJ Lead Solutions Architect

Roger Lau, APJ Lead Solutions Architect in Sonatype and an advocate of DevSecOps and Automation. With over 15 years of experience in software development, coupled with a diverse background and deep insights into the evolving threat landscape in open source component risks, he brings a unique perspective to helping organizations enrich their competitive edge through scalable and secure software supply chain practices.