BSides Canberra 2026

Paul McCarty

Paul is a serial startup found and a true hacker OG. He created OpenSourceMalware.com, the worlds largest open database and collaboration platform for software supply chain threat intel. Paul delivers software supply chain offensive security training and engagements globally and speaks at many security conferences and hacker meetups. He's spent many years hacking NPM and PyPI, and has made several discoveries about the ecosystem. Paul founded multiple startups starting in the '90s and has worked for NASA, Boeing, Blue Cross/Blue Shield, John Deere, the US military, the Australian government.  Paul is a frequent open-source contributor and author of several DevSecOps, software supply chain and threat modelling projects. He’s currently writing a book entitled “Hacking NPM”, and when he’s not doing that, he’s snowboarding with his wife and 3 amazing kids.


Session

09-26
09:00
390min
Software Supply Chain Threat Intelligence: Hands-On Training for SecOps and Threat Hunting Teams
Paul McCarty

Software supply chain attacks have become one of the most significant threats to organizations, with nation-state actors like DPRK's Lazarus Group actively compromising NPM packages, PyPI libraries, GitHub repositories, and VS Code extensions to target developers and steal credentials, cryptocurrency, and source code. This all-day hands-on training equips SecOps and threat hunting teams with practical skills to detect, analyze, and extract actionable threat intelligence from real-world supply chain malware—turning raw malware samples into finished intelligence products.

Participants will work directly with sanitized samples from active campaigns including Contagious Interview, PolinRider (DPRK), and Glassworm (Russia), analyzing malicious artifacts across four major attack surfaces: NPM, PyPI, GitHub, and VS Code extensions. Beyond technical analysis, attendees will learn about Paul's custom software supply chain CTI workflow: extracting IOCs, pivoting across infrastructure to identify campaign scope, attributing activity to threat actors, producing actionable reports, and alerting the community to the threats you expose. The training culminates with a 90-minute live hunting CTF-style session where participants apply their new skills to hunt for real threats and document findings using professional intelligence standards

Event Track
Murray-Fitzroy Room