In person

OWASP St. Louis

Join us for the OWASP St Louis Meetup: Lessons from npm's Dark Side - These Are Not the Packages You're Looking For

Malware is all about scale and time: How can I hit the most people in the shortest time? But not all ecosystems are equally vulnerable. The JavaScript ecosystem, particularly its package manager npm, is arguably the most vulnerable to supply chain malware attacks. And with JavaScript being the language of the web, this is a problem that impacts an estimated 27.4 million developers. So what are we to do? In this session learn about:

  • Why attackers target JavaScript/npm
  • A case study of 5 attacks
  • Whether we can trust maintainers to adopt security controls (research!)
  • What you can do to protect yourself and your company from malware
Date
January 13, 2026
Time
6:00PM - 7:30 PM
Location
North America
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Event Overview

Schedule

No items found.

Heading

No items found.
Event imageEvent imageEvent imageEvent imageEvent imageEvent imageEvent image
Event imageEvent imageEvent imageEvent imageEvent imageEvent imageEvent image
Event imageEvent imageEvent imageEvent imageEvent imageEvent imageEvent image
Event imageEvent imageEvent imageEvent imageEvent imageEvent imageEvent image

Want to stay in the loop?

Sign up for our newsletter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.