# CCT 366: Software Supply Chain Security Explained — CISSP Domain 8 (ChainDrop Case Study) Page: https://stenobird.com/podcast/cissp-cyber-training-podcast-cissp-training-program-6068495/cct-366-software-supply-chain-security-explained-cissp-domain-8-chaindrop-case-study Text version: https://stenobird.com/podcast/cissp-cyber-training-podcast-cissp-training-program-6068495/cct-366-software-supply-chain-security-explained-cissp-domain-8-chaindrop-case-study.md Podcast: [CISSP Cyber Training Podcast - CISSP Training Program](https://stenobird.com/podcast/cissp-cyber-training-podcast-cissp-training-program-6068495) Published: 2026-08-17T11:00:00+00:00 Episode link: https://www.buzzsprout.com/2167626/episodes/19652775-cct-366-software-supply-chain-security-explained-cissp-domain-8-chaindrop-case-study.mp3 Audio file: https://www.buzzsprout.com/2167626/episodes/19652775-cct-366-software-supply-chain-security-explained-cissp-domain-8-chaindrop-case-study.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cissp-cyber-training-podcast-cissp-training-program-6068495/episodes/cct-366-software-supply-chain-security-explained-cissp-domain-8-chaindrop-case-study Duration seconds: 1984 ## Resource Send us Fan Mail A supply chain attack that leaves your Git history spotless should change how you think about “secure code.” We walk through ChainDrop, a worm discovered in the NPM ecosystem that poisoned 444 packages while evading the places defenders usually look. The unnerving twist is that it can trigger without a classic npm install and can hide in the space between your repository and the package archive your CI/CD pipeline actually pulls, which is exactly why code review alone can’t b... ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cissp-cyber-training-podcast-cissp-training-program-6068495/episodes/cct-366-software-supply-chain-security-explained-cissp-domain-8-chaindrop-case-study/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cissp-cyber-training-podcast-cissp-training-program-6068495/cct-366-software-supply-chain-security-explained-cissp-domain-8-chaindrop-case-study.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.