Supply chain attacks are no longer a theoretical threat - they are a daily reality. GitHub repositories, npm packages, VS Code extensions, biggest open-source libraries: all have been weaponized to compromise thousands of developers and their users at once. New incidents surface every day, each one larger than the last, and no project is out of reach.
Every breach gets its post-mortem. But by the time you read it, the next attack is already being planned.
This talk is about getting ahead of it. We'll look at why anyone can fall victim, and, most importantly, what you can do about it. Small changes to how you work can cut your exposure dramatically. Not by becoming a security expert, but by learning to ask one uncomfortable question about everything you depend on: why do I trust this?
This talk has been presented at React Summit US 2026, check out the latest edition of this React Conference.























