Episode

#97 - Shift Left, Get Hacked: Supply Chain Attacks Hit Devs

Podcast
The DevSecOps Talks Podcast
Published
Apr 15, 2026
Duration seconds
2136
Processing state
not_requested
Canonical source
https://devsecops.podbean.com/e/97-shift-left-get-hacked-supply-chain-attacks-hit-devs/
Audio
https://mcdn.podbean.com/mf/web/zn4j9tz222sfwytw/097-shift-left-get-hacked-supply-chain-attacks-hit-devs.mp3
JSON
/v1/public/podcasts/the-devsecops-talks-podcast-1222637/episodes/97-shift-left-get-hacked-supply-chain-attacks-hit-devs
Markdown
/podcast/the-devsecops-talks-podcast-1222637/97-shift-left-get-hacked-supply-chain-attacks-hit-devs.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/the-devsecops-talks-podcast-1222637/episodes/97-shift-left-get-hacked-supply-chain-attacks-hit-devs/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/the-devsecops-talks-podcast-1222637/97-shift-left-get-hacked-supply-chain-attacks-hit-devs.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

March 2026 made supply chain attacks feel a lot less theoretical, but what made these incidents different? The hosts discuss compromised publishing credentials, automatic execution hooks like post-install scripts and Python `.pth` files, and how both humans and security tools caught the malicious releases. They also talk through concrete ways to make developer environments harder to abuse. We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.DevSecOps Talks podcast LinkedIn pageDevSecOps Talks podcast websiteDevSecOps Talks podcast YouTube channel