Session
Software Supply Chain Security in the Slopsquatting Era
Your AI coding assistant doesn't just write code for you. It also suggests packages and installs them in your project, often while you're looking at something else. These selections are part of your software supply chain, and are surprisingly easy to hijack.
When researchers tested 16 code-generating models, about 1 in 5 of the packages they recommended didn't exist at all, and 43% of those made-up names came back every single time they asked. Attackers are smart, so they register these names and just wait for somebody's tooling to install them. This style of attack is called slopsquatting.
The past twenty years of supply chain defenses assume a human does the installing, and that they might notice any package that was published last Tuesday with 12 downloads and an empty README. However, your agents don't always notice this. Your scanner tools might not either, because brand-new malware isn't on anybody's list yet.
In this talk we'll walk through how these attacks work, which of your legacy defenses still matter, and the process changes that will best protect you from this new threat.
Jonathan "J." Tower
VP of .NET Foundation | 13x Microsoft MVP | Founder & Consultant
Grand Rapids, Michigan, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top