Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

How Malicious NPM Packages Make Your Apps Vulnerable - SnykLIVE Recording

Snyk via YouTube

Overview

This course aims to educate developers on the susceptibility to malicious NPM packages and the potential risks they pose. By exploring various demos, participants will learn how malicious packages can modify code, affect package.json publish scripts, and more. The course equips learners with the knowledge to enhance their developer security skills and provides recommendations and open-source tools to prevent such attacks. The teaching method includes live demos and discussions, making it suitable for developers looking to strengthen their security practices in the software development process.

Syllabus

- Stream Start
- Introductions
- Audit-resolver Project
- How do Developers Install Malicious Packages?
- Demo: Malicious Package via postinstall script
- Demo: Malicious Package with TypeScript
- Demo: Malicious Package via Pipeline and prepublish script
- Recommendations to Stop These Attacks
- Some Open Source Tools to Help
- Conclusion
- Outro
- Stream End

Taught by

Snyk

Reviews

Start your review of How Malicious NPM Packages Make Your Apps Vulnerable - SnykLIVE Recording

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.