DOP 366: How to Prevent npm Supply Chain Attacks
Show Notes
#366: You ran npm install this morning. Maybe you ran it a dozen times. Every one of those pulled down a dependency tree you have never read, from a registry that spent years in maintenance mode, and then executed whatever preinstall and postinstall scripts happened to be in there. On your laptop. With your keys sitting on disk.
Trusted publishing, provenance, staged releases - all good, all recent, and none of it stops a package from shipping malware.
In this episode, we speak with David Mytton, CEO of Arcjet, about defense in depth for the npm ecosystem, and why seven days of patience beats most of your tooling.
Frequently Asked Questions
Why is running npm install a security risk?
How long should an npm dependency cooldown period be?
What is the difference between npm install and npm ci?
Does npm trusted publishing stop supply chain attacks?
How do you isolate a development environment from compromised npm packages?
How would you know if a compromised npm package ran on your laptop?
What is the DevOps Paradox podcast?
Episode Transcript
Share and Download
Guests
David Mytton
David Mytton is the Founder & CEO of Arcjet, a runtime security platform that provides developer building blocks to protect applications from bots & automation, prompt injection, AI tool abuse, and signup spam. He also writes the devtools newsletter console.dev.
Hosts
Viktor Farcic
Viktor Farcic is a member of the Google Developer Experts and Docker Captains groups, and published author.
His big passions are DevOps, Containers, Kubernetes, Microservices, Continuous Integration, Delivery and Deployment (CI/CD) and Test-Driven Development (TDD).
He often speaks at community gatherings and conferences.
He has published DevOps Paradox and Test-Driven Java Development.
His random thoughts and tutorials can be found in his blog The DevOps Toolkit.