← Back
Theo September 11, 2025 42m

This could have destroyed the entire web (the next one probably will)

Summary

A major supply chain attack targeted NPM, compromising 19 packages with over 2 billion downloads that attempted to steal cryptocurrency. Despite the alarming scale, the actual financial theft was minimal (less than 22 cents), and the malicious packages were quickly removed from the platform within 8 hours. The key focus is not on the immediate hack results, but understanding how such vulnerabilities emerge and developing strategies to prevent future supply chain security risks in software development ecosystems.

View original episode ↗