Security Weekly Podcast Network (Audio) cover image

Researching and Remediating RCEs via GitHub Actions - Bar Kaduri, Roi Nisimi - ASW #355

Security Weekly Podcast Network (Audio)

00:00

How can npm invisible dependencies hide malware?

Mike introduces the Phantom Raven NPM malware piece and the risk of packages resolving to external URLs that execute code during install.

Play episode from 51:46
Transcript

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app