
Hunt the Malicious Package: A Supply Chain CTF Workshop
About this event
io, Cloudsmith, and Chainguard to hunt a malicious package before production using SBOMs, AIBOMs, osv-scanner, and ClamAV. io. Visit the company-owned event page for the organizer's latest agenda, access details, availability, and registration or viewing instructions.
UPCOMING provides this independent listing to help professionals discover the session and routes outbound visitors to the official company source with referral attribution.
What you'll learn
- How to detect and trace a malicious package across npm and PyPI before it reaches production - How to use SBOMs and AI-BOMs to gain visibility into your dependencies and AI components - How a governed software supply chain can contain an incident before it spreads



