Lessons From NPMs Dark Side: Preventing the Next Shai-Hulud @FIRSTdotorg
Lessons From NPMs Dark Side: Preventing the Next Shai-Hulud  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 3 hours ago
Jenn Gile (OpenSourceMalware, US)

Malware is all about scale and time: How can I hit the most people in the shortest time? But not all ecosystems are equally vulnerable. The JavaScript ecosystem, particularly its package manager npm, is arguably the most vulnerable to supply chain malware attacks. And with JavaScript being the language of the web, this is a problem that impacts an estimated 27.4 million developers. So what are we to do?

---

Jenn Gile is a community builder and tech educator in the Security and DevOps fields. She's Co-Founder of OpenSourceMalware.com, on staff with BSides Seattle, and is an advisor at Endor Labs. Jenn previously worked at NGINX, F5, and the U.S. Department of State. Outside of work, she's deeply involved in the cycling community as a board member for 2nd Cycle.
Lessons From NPMs Dark Side: Preventing the Next Shai-HuludThe CVE Blind Spot: Defeating Hidden EOLs and Repo Jacking with Engineering Triage & Code DietAll Ransomware Economic Models are Wrong, But This One is UsefulCISA-ENISA Joint MessagingPanel: From Takedown to Touchpoint: An Inside Look at the Data-sharing Pipeline in the Victim ...Bringing Actionable Data to Internet DefendersUnlocking Insights: The Role of TI in Modern DFIR OperationsThe Quality Era of CVE: A Blueprint for Global Software SafetyBattle-Tested Incident Recovery: Lessons from the Front LinesThe AI Assistant’s Betrayal: One-Click for AI to Turn into the Perfect InsiderBoosting Vulnerability Intelligence: How Accurate CWE Mappings Transform ML Model PerformanceCan a General-Purpose LLM Do Tier-1 Triage?
FIRST |

Lessons From NPM's Dark Side: Preventing the Next Shai-Hulud

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER