Poisoned at the Source: Hacking the Software Supply Chain in Your CI/CD Pipeline
Last year's CI/CD attacks didn't come through the front door, they came pre-installed. In 2025, the Shai-Hulud worm tainted 500+ npm packages, the chalk/debug compromise hit packages with 2.6 billion weekly downloads, and axios was backdoored in a 3-hour window. In this hands-on workshop you'll become the attacker: build a malicious npm/PyPI package, poison a pipeline, exfiltrate secretss. Then switch hats and run the incident response, tracing the blast radius and learning the defenses that actually stop these attacks.
CI/CD pipelines run with god-tier privileges: they hold your cloud credentials, your signing keys, and your deploy access and they obediently execute code written minutes ago by people you've never met. That's not a bug, it's the feature. It's also the attack surface that defined 2025 in security.
This workshop is a practical, adversary-first tour of modern software supply chain attacks, built around a realistic vulnerable pipeline you'll attack end to end. Rather than abstract theory, you'll work through the full kill chain that real campaigns used this year.
You will:
- Build a malicious package, author an npm and/or PyPI package
- Poison the CI/CD pipeline, to gain code execution inside a build environment.
- Exfiltrate secrets, harvest environment variables, cloud tokens, and CI/CD credentials
- Switch to defense and respond flip to incident-response mode
Prerequisites: comfort with the command line and basic Git; familiarity with npm or pip is helpful but not required. Bring a laptop able to run Docker (a hosted lab option will be provided as fallback). All challenges run in isolated, disposable containers, no real registries are harmed.
Daniel Schwendner is a Cyber Security Specialist and former DevOps Engineer with a strong passion for Cyber Security. With a background in mobile application security and hardware security, he participates in bug bounty hunting and shares his security knowledge online.