Back to Talks 2022
Talk

NPM, "Private" Repos, and You

Recon Village @ DEF CON 3012th, 13th and 14th August 2022

Abstract

Supply chain research is so hot right now! In this talk I plan on talking about how to clone the NPM metadata database, and all of the interesting repercussions of this design decision. Between exposing code from private Github repos, being able to search through all contributors email addresses, cybersquatting maintainers expired domains for account takeovers, and the interactions between .gitignore and .npmignore, there's plenty of interesting things to be covered.

Speaker