Episode

How One Developer Took Down the Supply Chain

Podcast
Hacker And The Fed
Published
Apr 9, 2026
Duration seconds
2827
Processing state
not_requested
Canonical source
https://traffic.megaphone.fm/CON4484390968.mp3
Audio
https://traffic.megaphone.fm/CON4484390968.mp3
JSON
/v1/public/podcasts/hacker-and-the-fed-5741273/episodes/how-one-developer-took-down-the-supply-chain
Markdown
/podcast/hacker-and-the-fed-5741273/how-one-developer-took-down-the-supply-chain.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/hacker-and-the-fed-5741273/episodes/how-one-developer-took-down-the-supply-chain/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/hacker-and-the-fed-5741273/how-one-developer-took-down-the-supply-chain.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Chris and Hector break down a highly effective North Korean supply chain attack that started with a fake Microsoft Teams update and escalated into full developer compromise. They explore how modern attackers combine social engineering, open source manipulation, and long term access to infiltrate software pipelines. The episode also covers GitHub based attacks, compromised routers at scale, and why simple human pressure remains one of the most powerful tools in cybercrime. Join our Patreon for weekly bonus episodes: ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠https://www.patreon.com/c/hackerandthefed⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Send HATF your questions at ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠[email protected]