Jan. 24, 2024, 3:04 a.m. | OWASP Foundation

OWASP Foundation www.youtube.com

Slides: https://static.sched.com/hosted_files/owasp2023globalappsecwashin/93/OWASP%20DC%20Malicious%20Dependencies.pptx

Incidents of malicious dependencies in open source package managers continue to grow in number every year. However, we are not defenseless. Techniques to identify and neutralize malicious packages are also improving, and we add our own static analysis techniques to the mix.

Static analysis has become more accessible in recent years, making it a great tool for inspecting source code with speed and accuracy. By studying the code in malicious packages, combined with our own experience, we developed …

analysis code continue dependencies great identify incidents making malicious malicious packages managers open source own package package managers packages source code static analysis techniques tool

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)