Software supply chain attacks have become one of the most significant threats to organizations, with nation-state actors like DPRK's Lazarus Group, and TeamPCP actively compromising npm packages, PyPI libraries, GitHub repositories, and VS Code extensions to target developers and steal credentials, cryptocurrency, and source code. This hands-on training equips security teams with practical skills to detect, analyze, and extract actionable threat intelligence from real-world supply chain malware—turning raw malware samples into finished intelligence products.