Webinar: Wanted Dead or Alive: Hunt the Malicious Package

Jun 30, 2026

 

Malicious packages hit npm and PyPI every week, and most teams don’t catch them until production is already compromised. In this hands-on Capture the Flag workshop, Mend.io, Cloudsmith, and Chainguard drop you inside a breached company and challenge you to hunt down the malicious package before it ships. You’ll work with real open-source tools, expose the hidden risks of AI-driven development, and learn how a governed supply chain stops an attack before it starts.

In this webinar, you’ll learn:

  • How to detect and trace a malicious package across npm and PyPI before it reaches production
  • How to use SBOMs and AI-BOMs to gain visibility into your dependencies and AI components
  • How a governed software supply chain can contain an incident before it spreads

Speakers:

  • Amir Shahmiri, Senior Solutions Engineer – Mend.io
  • Nigel Douglas, Head of Developer Relations – Cloudsmith
  • Manfred Moser Sr, Principal DevRel Engineer – Chainguard