---
title: "Riding the Worm: Lessons from the NPM Supply Chain Attack"
url: "https://www.armorcode.com/podcast/riding-the-worm-lessons-from-the-npm-supply-chain-attack"
markdown_url: "https://www.armorcode.com/podcast/riding-the-worm-lessons-from-the-npm-supply-chain-attack.md"
llm_canonical: "https://www.armorcode.com/podcast/riding-the-worm-lessons-from-the-npm-supply-chain-attack.md"
canonical_for_llm: true
entity_type: "Article"
primary_entity: "Riding the Worm: Lessons from the NPM Supply Chain Attack"
citation_value: "Published on ArmorCode; canonical URL https://www.armorcode.com/podcast/riding-the-worm-lessons-from-the-npm-supply-chain-attack."
last_updated: "2025-09-23T14:50:23-07:00"
---

<h1>Riding the Worm: Lessons from the NPM Supply Chain Attack</h1>

Mark and Rohan break down the recent Shai-Hulud NPM supply chain attack, one of the most extensive JavaScript ecosystem compromises to date. They trace how a phishing campaign against NPM maintainers led to malicious package updates, the challenges in surfacing risks buried deep in dependency chains, and the implications for development teams shipping AI-generated code at scale. The discussion also explores how ArmorCode’s agentic AI, Anya, helps security teams detect anomalous package behavior by querying across code, pipelines, and deployments—before infected packages make it to production.
