Hunting the AI supply chain: from installation scripts to slopsquatting

Sep 24, 2026

 

Your AI stack is now part of your software supply chain, and almost nobody is hunting it. Pre-trained models, LLM code suggestions, and MCP-connected agents are new dependencies with their own attack paths, stacked on top of malicious packages, leaked secrets, and hijacked accounts. In this webinar, Mend.io’s research team runs real attacks on a developer machine and in a CI/CD pipeline, then shows you how to hunt them, from installation scripts to slopsquatting, poisoned models, and MCP “rug pulls”.

In this webinar, you’ll learn:

  • Three ways AI is expanding the software supply chain attack surface
  • How to hunt six supply chain threats: installation scripts, secrets leaks, malicious artifacts, repojacking, account takeover, and AI/ML supply chain threats
  • What slopsquatting is and why AI coding assistants make it easy for attackers to plant hallucinated packages
  • How malicious models and poisoned datasets evade scanners like PickleScan, and what to do instead
  • Practical steps for maintaining an AI-BOM, pinning models and MCP servers to verified versions, and reviewing AI-suggested dependencies before they ship

Speakers:

  • Gil Regev, GM Mend AI – Mend.io
  • Ashley Delfonso, Senior Product Marketing Manager – Mend.io