Demo: Defending Against npm Supply Chain Attacks.

Splunk
57 views January 27, 2026

This blog addresses all four challenges by introducing two complementary tools designed specifically for npm supply chain security: npm-threat-emulation for safe adversary simulation and Package-Inferno for deep package analysis. Together, they provide defenders with the capabilities needed to understand, detect, and respond to modern npm supply chain threats. The Splunk Threat Research Team (STRT) will also cover current npm attack scenarios and how we can use ESCU to hunt and detect malicious behavior.

Keyboard shortcuts

On. Switch them off if they collide with your assistive tools; ? still opens this sheet.

Go to

Press g then the letter.

  • gh Latest
  • gs Sources
  • gm Media
  • gv Videos
  • gp Podcasts
  • gc Calendar
  • gd Decoder
  • gz Dataviz
  • ga Datasets
  • gb Blog
  • gk Markets
  • gj Careers
  • gn Prompt Notebook

On this page

  • / Focus search, where there is one
  • t Back to top
  • ? This list
  • Esc Close