惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
人人都是产品经理
人人都是产品经理
爱范儿
爱范儿
云风的 BLOG
云风的 BLOG
Last Week in AI
Last Week in AI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
B
Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
H
Help Net Security
B
Blog RSS Feed
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
N
Netflix TechBlog - Medium
S
SegmentFault 最新的问题
The Cloudflare Blog
I
InfoQ
美团技术团队
博客园 - 三生石上(FineUI控件)
MyScale Blog
MyScale Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 司徒正美
L
LangChain Blog
A
About on SuperTechFans
T
The Blog of Author Tim Ferriss
Y
Y Combinator Blog

Risky Business Features

How to launder illicit Bitcoin Hunting software supply chain malware Who gets to hack the hackers? How Brian Krebs doxxed TeamPCP James Kettle on inventing new attack techniques with LLMs How private LLM inference actually works Benchmarks, borders and the true cost of AI regulation Fortibleed: The bleeding edge of AI cybercrime What to do 'til the bugpocalypse gets here Mythos on your desk? Using local LLMs for code reviews Pitching security startups to VCs in the AI era How using open weight models can blow up in your face The state of the art in AI model jailbreaks Everything is getting much worse, much faster Solo podcast: A deep dive on TeamPCP How to survive supply chain attacks How the CopyFail disclosure went sideways NCSC’s Ollie Whitehouse on surviving the "bugpocalypse" What a great agentic AI deployment plan looks like Mythos smythos! How to find 0day with lesser models Solving the AI agent identity problem A deep dive on AI model distillation attacks Feature Interview: Nicholas Carlini, Anthropic A builder's perspective on Mythos and frontier models Mythos and 0day: Fixing exploits is not safety Mythos and 0day: A hacker’s perspective What happens after North Korea infiltrates? Why CISOs need to be more flexible in the AI era A Risky Biz Experiment: Hunting for iOS 0day with AI Interview: Former NSA and CIA cyber leaders on offensive AI
Why NPM v12 won’t stop supply chain attacks
James Wilson · 2026-06-12 · via Risky Business Features

Risky Business Features Podcast

June 12, 2026

Presented by

James Wilson

James Wilson

Technology Editor

In this podcast episode, James Wilson is joined by Open Source Malware Security co-founder Paul McCarty to talk about the supply chain attack mitigations coming in NPM v12.

NPM disabling (by default) auto-run install scripts and dynamic dependencies is a positive step forward… but it’ll take years for this new version to be adopted, and these changes do nothing to prevent malicious packages being imported into projects.

Further, Paul thinks disabling these features by default will introduce friction that will cause them to be re-enabled. When the choice is “this builds” and “this is less prone to malware”, the former will always win.

Your browser does not support the audio element.

Why NPM v12 won’t stop supply chain attacks

0:00 / 38:32

Logo