2026-09-11 –, Uni Campus Seminarhaus 4
Software supply chain attacks have become one of the most significant threats to organizations, with nation-state actors like DPRK's Lazarus Group, and TeamPCP actively compromising npm packages, PyPI libraries, GitHub repositories, and VS Code extensions to target developers and steal credentials, cryptocurrency, and source code. This hands-on training equips security teams with practical skills to detect, analyze, and extract actionable threat intelligence from real-world supply chain malware—turning raw malware samples into finished intelligence products.
Participants will work directly with sanitized samples from active campaigns including Contagious Interview (BeaverTail/InvisibleFerret), Glassworm, and TeamPCP/Miasma. The attendees will analyze malicious artifacts across four major attack surfaces: npm, PyPI, GitHub, and VS Code extensions. Beyond technical analysis, attendees will learn the trainers custom software supply chain CTI workflow: extracting IOCs, pivoting across infrastructure to identify campaign scope, attributing activity to threat actors, , producing actionable reports and alerting the community to the threats you expose. The training culminates with a live hunting session where participants apply their new skills to hunt for real threats and document findings using professional intelligence standards.