Vigyata.AI
Is this your channel?

DEF CON 33 - How malicious packages on npm bypass existing security tools - Paul McCarty

1.1K views· 35 likes· 32:39· Oct 10, 2025

npm is owned by Microsoft and is the world’s largest software registry. It hosts nearly 5 million packages and 4.5 trillion requests for packages were made to npm in 2024. The open and accessible nature of npm is one of its main features, but it's also one of the reasons that threat actors are attracted to it. A recent study by Sonatype found that 98.5% of malicious software packages are hosted and delivered via npm This technical deep-dive will explain why npm is so good at delivering malware; expose how threat actors are using npm; and why existing security tools like SCA, SAST, EDR and anti-virus solutions will not protect you from npm based malware..

🎬 More from DEFCONConference