Demo: Defending Against npm Supply Chain Attacks.
This blog addresses all four challenges by introducing two complementary tools designed specifically for npm supply chain security: npm-threat-emulation for safe adversary simulation and Package-Inferno for deep package analysis. Together, they provide defenders with the capabilities needed to understand, detect, and respond to modern npm supply chain threats. The Splunk Threat Research Team (STRT) will also cover current npm attack scenarios and how we can use ESCU to hunt and detect malicious behavior.