Software Supply Chain Attacks - A Silent Killer

Security Days Fall 2026

25 March 2026

WS2-03 | March 25 (Wed) 10:00-11:30 | 5F | Workshop | Consecutive Translation

Workshop Overview

Software supply chain attacks don’t start at package managers: they start at developer laptops, compromised credentials, and CI/CD missteps. This session walks through a real-world attack from dev environment compromise to poisoned builds and eventual deployment of a backdoored release. It’s not theory — it’s how breaches actually unfold. We will relate each step with real life attacks that have happened along the way.

Learning Outcomes

Audience Level

Beginner — The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.

Prerequisites

  1. Personal Laptop with unrestricted internet access
  2. Google Account with Access to Google Cloud Console & Cloud Shell (reference)
  3. Personal GitHub Account
  4. VSCode/Cursor installed on your personal laptop
  5. Discord Account for support

Due to the short duration of the workshop, dedicated troubleshooting support is not provided. If your system does not work, the recommended approach is to observe how others are progressing and try again after the workshop.

Event Information