DevSec Station
Malicious dependencies are not accidents. They are often intentionally designed to look trustworthy so developers install them without hesitation. In this episode of DevSec Station, Tanya Janca [https://tanyajanca.com] explains how attackers use typosquatting, dependency confusion, fake packages, and even AI-generated recommendations to compromise developer environments and steal credentials. This episode is sponsored by Maze. [https://mazehq.com/devsec] You’ll learn: • how malicious packages trick developers • why dependency attacks work so well • how attackers abuse trust and speed • why “just be careful” is not an effective defense • practical ways to add safer guardrails to your development workflow Tanya walks through a realistic example of a dependency stealing AWS credentials, explains why this is a workflow problem instead of a developer failure, and shares practical steps you can take immediately to reduce risk in your own projects. One practical action from this episode: Require new dependencies to go through pull request review, and add lightweight checks that help your team verify package names and sources before installation. DevSec Station is a podcast by Tanya Janca, focused on short, practical lessons that help software developers build more secure software. Follow Tanya: • https://shehackspurple.ca [https://shehackspurple.ca ] • https://newsletter.shehackspurple.ca [https://newsletter.shehackspurple.ca] • https://linkedin.com/in/tanya-janca [https://linkedin.com/in/tanya-janca] • https://www.youtube.com/shehackspurple [https://www.youtube.com/shehackspurple] • https://TanyaJanca.com [https://www.youtube.com/shehackspurple] This episode is sponsored by Maze. One of the biggest problems in security right now is that every vulnerability (or cloud?) scanner says everything is critical, and honestly, no one has time for that. Maze uses AI agents to investigate vulnerabilities in context, so you can focus on the issues that are actually exploitable in your environment, not just theoretically scary. Their AI agents also generate and prioritize fixes that knock out multiple vulnerabilities at once, which is honestly the kind of scaling that security teams need right now. Learn more about Maze mazehq.com/devsec [https://mazehq.com/devsec]
4 afleveringen
Reacties
0Wees de eerste die een reactie plaatst
Meld je nu aan en word lid van de DevSec Station community!