BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//Khoury College of Computer Sciences - ECPv6.17.2//NONSGML v1.0//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-ORIGINAL-URL:https://www.khoury.northeastern.edu
X-WR-CALDESC:Events for Khoury College of Computer Sciences
REFRESH-INTERVAL;VALUE=DURATION:PT1H
X-Robots-Tag:noindex
X-PUBLISHED-TTL:PT1H
BEGIN:VTIMEZONE
TZID:America/New_York
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20250309T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20251102T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20260308T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20261101T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20270314T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20271107T060000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20261105T160000
DTEND;TZID=America/New_York:20261105T180000
DTSTAMP:20260805T202055Z
CREATED:20260805T142436Z
LAST-MODIFIED:20260805T202055Z
UID:10006664-1793894400-1793901600@www.khoury.northeastern.edu
SUMMARY:Seminar: Malicious npm Packages — Anatomy\, Detection Gaps\, and AI's Role (Boston)
DESCRIPTION:Register now\n\n\n\n\nThis seminar examines the modern software supply chain threat landscape through the lens of the JavaScript ecosystem\, drawing on analysis of real 2025 compromises including the NX Singularity\, Chalk/Debug\, and Shai-Hulud campaigns. It explores how attackers infiltrate npm through typosquatting\, dependency confusion\, and maintainer account takeovers\, and how payloads are delivered using install-time hooks\, obfuscated JavaScript\, bundled binaries\, and worm-style propagation. A central focus is the window-of-exposure problem: the gap between a malicious publish and a public advisory is the true attack surface. The session also evaluates the role of AI-assisted analysis across varying obfuscation tiers such as readable\, minified\, and fully obfuscated code\, bundled binaries and concludes with concrete\, actionable defenses practitioners can apply immediately. \n\n\n\nPresenter: Diptendu Kar\n\n\n\nDiptendu Kar is a security researcher focused on supply chain and dependency risk. He works on triaging open-source vulnerabilities\, writing detection rules\, and exploring how AI can automate tedious parts of security research. He is a Northeastern University alumnus and previously served as a part-time instructor at Khoury College\, teaching CY6120: Software Security Practices. He is especially interested in patch diffing\, vulnerable function detection\, and the use of LLMs in AppSec. He is a frequent speaker at security conferences such as OWASP and BSides. \n\n\n\n\nRegister now
URL:https://www.khoury.northeastern.edu/event/seminar-malicious-npm-packages-anatomy-detection-gaps-and-ais-role-boston/
LOCATION:366 West Village H\, 440 Huntington Avenue\, Boston\, MA\, 02115\, United States
CATEGORIES:Research
GEO:42.3386529;-71.0921979
X-APPLE-STRUCTURED-LOCATION;VALUE=URI;X-ADDRESS=366 West Village H 440 Huntington Avenue Boston MA 02115 United States;X-APPLE-RADIUS=500;X-TITLE=440 Huntington Avenue:geo:-71.0921979,42.3386529
END:VEVENT
END:VCALENDAR