Uploaded April 2026 | Updated September 2026, 21 hours ago
Most supply chain attacks don’t target production—they exploit the build. This session unpacks how and where malware slips into builds, with a look at recent real-world attacks and what could’ve stopped them. We’ll show how Chainguard Libraries, by building from source with full provenance, blocked ~99.7% of known malicious npm packages in testing. Learn how build-time protection changes the game, and walk away with practical strategies to get started with Chainguard Libraries.
TIMESTAMPS
0:00 Introduction
1:00 Public repositories under strain and software supply chain attacks
3:40 Incidents
5:10 Software supply chain introduction
8:17 Attack example: Solarwinds/Sunburst
9:42 Attack example: log4shell
11:26 Attack example: PyTorch dependency confusion
13:21 Attack example: Ultralytics YOLO
14:20 Software supply chain and malware
16:09 Sampler of noteworthy attacks with different methods
19:25 Shai-Hulud and other worms
21:34 Chainguard Libraries intro and Chainguard Factory
24:55 Future threads and trends
30:30 Question about library version conflict and latest tag
35:05 Question about zero trust, malware scanning, and Chainguard Factory
41:22 Question about Chainguard Repository
About Chainguard
Founded by the industry's leading experts on open source software, security and cloud native development, we are on a mission to be the safe source for open source.
Where to find us:
Website: https://www.chainguard.dev/
Twitter: twitter.com/chainguard_dev
LinkedIn: linkedin.com/company/chainguard-dev
TikTok: tiktok.com/@chainguard_dev
Most supply chain attacks don’t target production—they exploit the build. This session unpacks how and where malware slips into builds, with a look at recent real-world attacks and what could’ve stopped them. We’ll show how Chainguard Libraries, by building from source with full provenance, blocked ~99.7% of known malicious npm packages in testing. Learn how build-time protection changes the game, and walk away with practical strategies to get started with Chainguard Libraries.
TIMESTAMPS
0:00 Introduction
1:00 Public repositories under strain and software supply chain attacks
3:40 Incidents
5:10 Software supply chain introduction
8:17 Attack example: Solarwinds/Sunburst
9:42 Attack example: log4shell
11:26 Attack example: PyTorch dependency confusion
13:21 Attack example: Ultralytics YOLO
14:20 Software supply chain and malware
16:09 Sampler of noteworthy attacks with different methods
19:25 Shai-Hulud and other worms
21:34 Chainguard Libraries intro and Chainguard Factory
24:55 Future threads and trends
30:30 Question about library version conflict and latest tag
35:05 Question about zero trust, malware scanning, and Chainguard Factory
41:22 Question about Chainguard Repository
About Chainguard
Founded by the industry's leading experts on open source software, security and cloud native development, we are on a mission to be the safe source for open source.
Where to find us:
Website: https://www.chainguard.dev/
Twitter: twitter.com/chainguard_dev
LinkedIn: linkedin.com/company/chainguard-dev
TikTok: tiktok.com/@chainguard_dev










