# #97 - Shift Left, Get Hacked: Supply Chain Attacks Hit Devs Page: https://stenobird.com/podcast/the-devsecops-talks-podcast-1222637/97-shift-left-get-hacked-supply-chain-attacks-hit-devs Text version: https://stenobird.com/podcast/the-devsecops-talks-podcast-1222637/97-shift-left-get-hacked-supply-chain-attacks-hit-devs.md Podcast: [The DevSecOps Talks Podcast](https://stenobird.com/podcast/the-devsecops-talks-podcast-1222637) Published: 2026-04-15T23:20:16+00:00 Episode link: https://devsecops.podbean.com/e/97-shift-left-get-hacked-supply-chain-attacks-hit-devs/ Audio file: https://mcdn.podbean.com/mf/web/zn4j9tz222sfwytw/097-shift-left-get-hacked-supply-chain-attacks-hit-devs.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/the-devsecops-talks-podcast-1222637/episodes/97-shift-left-get-hacked-supply-chain-attacks-hit-devs Duration seconds: 2136 ## Resource March 2026 made supply chain attacks feel a lot less theoretical, but what made these incidents different? The hosts discuss compromised publishing credentials, automatic execution hooks like post-install scripts and Python `.pth` files, and how both humans and security tools caught the malicious releases. They also talk through concrete ways to make developer environments harder to abuse. We are always happy to answer any questions, hear suggestions for new episodes, or hear from you, our listeners.DevSecOps Talks podcast LinkedIn pageDevSecOps Talks podcast websiteDevSecOps Talks podcast YouTube channel ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/the-devsecops-talks-podcast-1222637/episodes/97-shift-left-get-hacked-supply-chain-attacks-hit-devs/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/the-devsecops-talks-podcast-1222637/97-shift-left-get-hacked-supply-chain-attacks-hit-devs.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.