Uploaded August 2026 | Updated September 2026, 32 minutes ago
Harish Shankar (Schneider Electric, IN)
The JavaScript ecosystem has become a primary target for sophisticated supply chain attacks, with NPM—the package manager for 3M+ code packages serving billions of installations. This presentation analyses the anatomy of modern NPM compromises, from initial attack vectors through autonomous propagation mechanisms, and provides actionable defence strategies.
Attendees will understand how attackers exploit NPM's centralized model through phishing (npmjs.help spoofing), CI/CD token theft via infostealer malware, and typosquatting to achieve account compromise. We'll examine the September 2025 attack that compromised a single maintainer account to reach 2.6 billion weekly downloads across 18 packages, and the Shai-Hulud worm that autonomously infected 27,000+ repositories by exploiting transitive dependencies.
The presentation will dissect the evolving attack workflow: multi‑stage payloads, environmental fingerprinting, GitHub Actions backdoors, credential harvesting via TruffleHog integration, and self‑replicating worm mechanisms that create exponential impact from minimal attacker exposure. Real-world payload analysis demonstrates cryptocurrency theft, cryptomining, and destructive fallbacks.
Finally, we'll address practical countermeasures: SCA tools with behavioral detection, strict version pinning with lifecycle hook blocking, private registry/proxy implementations, ephemeral token strategies, and organizational incident response playbooks and essential controls as supply chain attacks are expected to scale up.
---
Harish Shankar is currently working as Director – Head of Product Vulnerability Management in Schneider Electric. In this role, he heads Schneider Electric’s PSIRT Team which is represented as SE - Corporate Product Cyber Emergency Response Team (CPCERT) where he is responsible for defining and governing product vulnerability response.Prior to this role, he handled Product Incident Response and has hands-on experience on Incident Response and Digital Forensics. He also held the positions of Information Security Officer for the APAC region in Schneider Electric.
Harish Shankar (Schneider Electric, IN)
The JavaScript ecosystem has become a primary target for sophisticated supply chain attacks, with NPM—the package manager for 3M+ code packages serving billions of installations. This presentation analyses the anatomy of modern NPM compromises, from initial attack vectors through autonomous propagation mechanisms, and provides actionable defence strategies.
Attendees will understand how attackers exploit NPM's centralized model through phishing (npmjs.help spoofing), CI/CD token theft via infostealer malware, and typosquatting to achieve account compromise. We'll examine the September 2025 attack that compromised a single maintainer account to reach 2.6 billion weekly downloads across 18 packages, and the Shai-Hulud worm that autonomously infected 27,000+ repositories by exploiting transitive dependencies.
The presentation will dissect the evolving attack workflow: multi‑stage payloads, environmental fingerprinting, GitHub Actions backdoors, credential harvesting via TruffleHog integration, and self‑replicating worm mechanisms that create exponential impact from minimal attacker exposure. Real-world payload analysis demonstrates cryptocurrency theft, cryptomining, and destructive fallbacks.
Finally, we'll address practical countermeasures: SCA tools with behavioral detection, strict version pinning with lifecycle hook blocking, private registry/proxy implementations, ephemeral token strategies, and organizational incident response playbooks and essential controls as supply chain attacks are expected to scale up.
---
Harish Shankar is currently working as Director – Head of Product Vulnerability Management in Schneider Electric. In this role, he heads Schneider Electric’s PSIRT Team which is represented as SE - Corporate Product Cyber Emergency Response Team (CPCERT) where he is responsible for defining and governing product vulnerability response.Prior to this role, he handled Product Incident Response and has hands-on experience on Incident Response and Digital Forensics. He also held the positions of Information Security Officer for the APAC region in Schneider Electric.










