BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Hunting GitHub to identify adversary TTPs in the wil
 d\n   Tags: Adversary Village | Creator Workshop\n   When: Friday\, Aug 7\
 , 13:00 - 14:55 PDT\n   Where: LVCCW Level 1 Hall 2 602 (Adversary Village
 ) Workshop Stage -\n   [1]Map\n\n   Description:\n\n   This hands-on works
 hop at Adversary Village RSAC 2026 provides a\n   20-minute deep dive into
  software supply chain attacks through\n   practical exercises. The sessio
 n will focus on the TTPs that\n   DPRK-affiliated threat actors use to com
 promise software engineers\,\n   with particular emphasis on "Contagious I
 nterview" campaigns.\n   Participants will engage in CTI-based targeting a
 nd identification of\n   key techniques\, blending practical hunting exerc
 ises in GitHub and NPM\n   to discover malicious packages and repositories
  in the wild with\n   adversary emulation scenarios that walk through the 
 complete attack\n   chain.\n\n   The workshop will demonstrate how threat 
 actors evade detection\, while\n   also teaching defenders how to detect a
 nd prevent these increasingly\n   common supply chain threats. By experien
 cing these attacks from the\n   adversary's perspective\, participants wil
 l gain critical insights into\n   real-world compromise techniques.\n\n   
 Things we will hunt for in GitHub and NPM:\n\n     1. \n\n       VS Code t
 asks files - RCE via automatic execution of the tasks\n       file when co
 mpromised source code is opened in VS Code\n\n     2. \n\n       Fake font
 s - hidden JavaScript payloads pretending to be font\n       files\n\n    
  3. \n\n       Fake VS Code dictionary files that hide JavaScript payloads
 \n\n     4. \n\n       "PolinRider" TTPs for specific JavaScript payload a
 ppending\n\n     5. \n\n       How DPRK threat actors hide infrastructure 
 in cloud providers\n\n     6. \n\n       Malicious npm packages with obfus
 cated payloads in install hooks\n\n     7. \n\n       Dependency confusion
  attacks targeting internal package names\n\n     8. \n\n       Backstoppe
 d GitHub repositories with fabricated commit histories\n\n   Speakers:Paul
  McCarty\,Jenn Gile\n\n   SpeakerBio:  Paul McCarty\, Founder and lead res
 earcher at\n   OpenSourceMalware\, the software supply chain threat intell
 igence\n   platform. Software supply chain offensive security crazy person
 .\n\n   Paul is the founder and maintainer of OpenSourceMalware\, the worl
 d's\n   largest open database and collaboration platform for software supp
 ly\n   chain threat intel. His day job is Head of Research at Safety and i
 s a\n   DevSecOps OG. He loves software supply chain research and deliveri
 ng\n   supply chain offensive security training and engagements. He's spen
 t\n   the last two years deep-diving into npm and has made several\n   dis
 coveries about the ecosystem. Paul founded multiple startups\n   starting 
 in the '90s and has worked for NASA\, Boeing\, Blue Cross/Blue\n   Shield\
 , John Deere\, the US military\, and the Australian government.\n   Ā Paul
  is a frequent open-source contributor and author of several\n   DevSecOps
 \, software supply chain and threat modelling projects. Heās\n   current
 ly writing a book entitled āHacking NPMā\, and when heās\n   not doi
 ng that\, heās snowboarding with his wife and 3 amazing kids.\n\n   Spea
 kerBio:  Jenn Gile\n\n   Jenn Gile is a community builder and tech educato
 r in the Security and\n   DevOps fields. She's Co-Founder of OpenSourceMal
 ware.com and runs the\n   community program for BSides Seattle. Jenn previ
 ously worked at NGINX\,\n   F5\, Endor Labs\, and the U.S. Department of S
 tate. Outside of work\,\n   she's deeply involved in the cycling community
  as a board member for\n   2nd Cycle.\n\n   Links:\n       adversaryvillag
 e.org/adversary-events/DEFCON-34/ - [2]https://adversaryvillage.org/advers
 ary-events/DEFCON-34/\n   '\n\n   1. #LVCCW_Level1_Hall2\n   2. https://ad
 versaryvillage.org/adversary-events/DEFCON-34/\n\n\n
DTEND:20260807T215500Z
DTSTART:20260807T200000Z
LOCATION:Adversary Village - LVCCW Level 1 Hall 2 602 (Adversary Village) W
 orkshop Stage
SUMMARY:Hunting GitHub to identify adversary TTPs in the wild
END:VEVENT
END:VCALENDAR
