Uploaded May 2026 | Updated September 2026, 2 weeks ago
π Your npm install can steal your secrets β and your AI assistant might help it do that π In this talk, Jo Franchetti breaks down real supply chain attacks and shows how to run untrusted code (including AI-generated) in complete isolation β no Docker required π₯
What's inside:
πΉ How the Shai-Hulud worm turned 1,300+ npm packages into attack vectors automatically
πΉ The Chalk attack: a phishing email β 2 billion weekly downloads compromised
πΉ Why --ignore-scripts doesn't save you at runtime
πΉ Deno's permission system stopping credential theft live on stage
πΉ Why AI-generated code is structurally less reviewed β and why that matters
πΉ 12,000 live API keys in AI training data + a real GitHub Copilot CVE
πΉ MicroVM sandboxes that start in 200ms β no Docker needed
πΉ How to pass API keys to untrusted code without the code ever seeing them
π₯ Jo Franchetti is a Software Engineer and Developer Advocate passionate about developer experience, TypeScript, and teaching good use of the web. Beyond the code, Jo mentors junior developers, actively advocates for mental health awareness in tech, and works to make the industry more diverse and inclusive.
π Connect with Jo:
π https://x.com/thisisjofrank
π github.com/thisisjofrank
Click the Related video to watch the full talk on YouTube!
#nodejs #javascript #npm #denosecurity #supplychainattack #cybersecurity #webdev #typescript #deno #npmpackages #softwaresecurity #devops #aicoding #promptinjection #sandboxing #microvm #appsecurity #dependencysecurity #javascriptdeveloper #securecoding #aitools #githubcopilot #llmsecurity #nodecongress #backenddevelopment #softwareengineering #devsecops #malware #opensouce #codesecurity
π Your npm install can steal your secrets β and your AI assistant might help it do that π In this talk, Jo Franchetti breaks down real supply chain attacks and shows how to run untrusted code (including AI-generated) in complete isolation β no Docker required π₯
What's inside:
πΉ How the Shai-Hulud worm turned 1,300+ npm packages into attack vectors automatically
πΉ The Chalk attack: a phishing email β 2 billion weekly downloads compromised
πΉ Why --ignore-scripts doesn't save you at runtime
πΉ Deno's permission system stopping credential theft live on stage
πΉ Why AI-generated code is structurally less reviewed β and why that matters
πΉ 12,000 live API keys in AI training data + a real GitHub Copilot CVE
πΉ MicroVM sandboxes that start in 200ms β no Docker needed
πΉ How to pass API keys to untrusted code without the code ever seeing them
π₯ Jo Franchetti is a Software Engineer and Developer Advocate passionate about developer experience, TypeScript, and teaching good use of the web. Beyond the code, Jo mentors junior developers, actively advocates for mental health awareness in tech, and works to make the industry more diverse and inclusive.
π Connect with Jo:
π https://x.com/thisisjofrank
π github.com/thisisjofrank
Click the Related video to watch the full talk on YouTube!
#nodejs #javascript #npm #denosecurity #supplychainattack #cybersecurity #webdev #typescript #deno #npmpackages #softwaresecurity #devops #aicoding #promptinjection #sandboxing #microvm #appsecurity #dependencysecurity #javascriptdeveloper #securecoding #aitools #githubcopilot #llmsecurity #nodecongress #backenddevelopment #softwareengineering #devsecops #malware #opensouce #codesecurity










