BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Anatomy of a Sandworm: A Deep Dive into the Shai-Hul
 ud Attacks\n   Tags: Malware Village | Creator Talk/Panel\n   When: Friday
 \, Aug 7\, 10:00 - 10:45 PDT\n   Where: LVCCW Level 1 Hall 2 600 (Malware 
 Village) Talks - [1]Map\n\n   Description:\n   Format: Talk\n   Length: 20
 -40min (I'm flexible\, I can adjust the content based on how\n   long the 
 time slot is)\n\n   Abstract: In September 2025\, an obscure npm package s
 hipped with a\n   piece of JavaScript that should not have been there. A n
 ew beast had\n   emerged among supply chain attacks. Within 48 hours\, tha
 t JavaScript\n   had copied itself into more than 180 packages. It did som
 ething that\n   hadn't been seen before in such an attack. It was self-pro
 pagating. It\n   was a worm. And it was LOUD. Hundreds of public repos wer
 e created\,\n   littered with stolen secrets. Within nine days\, it had tr
 iggered an\n   emergency CISA alert.\n\n   Two months later\, we witnessed
  the "Second Coming": a far more\n   aggressive successor returned\, racin
 g a deadline npm itself had set\,\n   and leaving behind roughly 700 compr
 omised packages\, ~25\,000 GitHub\n   repositories of stolen secrets\, and
  a destructive payload that wiped\n   victims' home directories when it co
 uldn't exfiltrate them. And these\n   were just the first two attacks.\n\n
    This talk is a technical breakdown of the Shai-Hulud worm family: the\n
    first malware to spread successfully through the npm ecosystem as a\n  
  self-replicating worm\, and the iterations that followed. We'll examine\n
    how the malware infected its victims\, turned legitimate security\n   t
 ooling against them\, what it stole\, and how it kept spreading.\n\n   Eac
 h iteration evolved to defeat the defenses put in place against the\n   la
 st\, swapping tools\, tactics\, and even its JavaScript runtime.\n   Stran
 ger still: the malware wasn't trying to hide. It branded its own\n   exfil
 tration repositories\, named its propagation functions clearly in\n   sour
 ce\, and used victims' own GitHub accounts to share stolen secrets.\n   By
  the end\, we'll have a clearer picture of how these supply chain\n   worm
 s work\, and what each rising of Shai-Hulud has taught us.\n\n   SpeakerBi
 o:  Megg Sage\, AppSec engineer who explains scary things\n   about your d
 ependencies\n\n   Megg is an application security engineer who started out
  as a web\n   developer. Security drew her in with the endless puzzles and
 \n   challenges put forth by the field. She loves sharing knowledge\,\n   
 particularly when she can both educate and frighten her audience at\n   th
 e same time. After all\, what can happen when security goes wrong is\n   p
 retty scary. She also enjoys working closely with software\n   engineering
  teams to try to make security work within existing\n   development practi
 ces or at least minimize the pain of "doing\n   security." When not behind
  a computer\, Megg can usually be found\n   making some sort of costume pi
 ece or shiny object.\n\n   '\n\n   1. #LVCCW_Level1_Hall2\n\n\n
DTEND:20260807T174500Z
DTSTART:20260807T170000Z
LOCATION:Malware Village - LVCCW Level 1 Hall 2 600 (Malware Village) Talks
SUMMARY:Anatomy of a Sandworm: A Deep Dive into the Shai-Hulud Attacks
END:VEVENT
END:VCALENDAR
