Bad Dependencies Podcast
In this episode of Bad Dependencies, host Mackenzie Jackson sits down with security researcher Charlie Eriksen to dissect a massive software supply chain attack hitting the Mastra AI ecosystem. Breaking down how an attacker compromised a maintainer's account to inject a malicious transitive dependency (easy-day-js) across over 140 packages, they explore the sophisticated social engineering tactics behind the breach. The duo also discusses critical defensive strategies—from package manager cooldown periods to upcoming NPM security changes—and warns developers about why build pipelines have become the latest critical attack surface. Chapters * 00:00 – Introduction * 00:28 – The Mastra AI Ecosystem Attack Explained * 02:18 – The Payload: Remote Access Trojans (RATs) & Crypto Stealers * 03:26 – Phishing the Maintainer: The "Microphone Trick" & North Korea * 05:45 – Reach of the Attack & Incident Response Playbook * 08:47 – Preventative Measures: Cooldown Windows & Closing the OIDC Door * 13:08 – NPM Version 12 and the End of Post-Install Scripts * 16:05 – The Next Attack Surface: GitHub Actions & Governance * 20:06 – Outro (And One Last Bad Vibe)
14 jaksot
Kommentit
0Ole ensimmäinen kommentoija
Rekisteröidy nyt ja liity Bad Dependencies Podcast-yhteisöön!