Skip to main content
Software Engineering Daily

AI-Powered Threats to the Software Supply Chain

57 min episode · 2 min read
·
Matt Moore

Episode

57 min

Read time

2 min

Topics

Fundraising & VC, Artificial Intelligence, Software Development

AI-Generated Summary

Key Takeaways

  • Build from source to eliminate malware classes: Constructing packages directly from source code — rather than pulling pre-built artifacts from public registries like PyPI or npm — eliminates 98–99% of the attack vectors used in recent malware campaigns. Chainguard's library product blocked every malware attack targeting its customers over the past several months using this approach.
  • Short-lived credentials are non-negotiable in CI/CD: Nearly every major supply chain attack, including TJ Actions and Shailood, succeeded by exfiltrating long-lived credentials from CI/CD pipelines. Chainguard built OktoSCS, a free public credential federation service for GitHub, that issues only short-lived tokens backed by a KMS system requiring security team approval to access the underlying secret.
  • SBOM coverage percentage matters more than SBOM existence: Mandatory SBOM requirements in frameworks like the EU Cyber Resilience Act are insufficient without specifying coverage depth, format, and resolution. An SBOM covering only 10% of files in a container image technically satisfies schema requirements. Chainguard's approach ensures every file traces back to a versioned package, achieving near-100% provenance coverage.
  • Patch at machine speed or face compounding risk from AI vulnerability discovery: Anthropic's Claude Opus 4 found 10–20x more CVEs in a recent Firefox release than prior tooling. The model chains multiple vulnerabilities together to identify exploits that single-flaw scanners miss. Organizations not already automating patch pipelines will face a backlog of newly discovered, weaponizable vulnerabilities within the next six to twelve months.
  • Behavioral scanning catches grayware that signature tools miss: Beyond known malware signatures, scanning for anomalous syscall patterns between package versions — such as a patch release suddenly opening new network connections — flags both compromised and "grayware" packages. Differential scanning between dot-one and dot-two releases detects unexpected behavioral changes before a malicious build is published.

What It Covers

Chainguard CTO Matt Moore joins Software Engineering Daily to examine how software supply chain attacks have escalated from rare events to daily occurrences, covering the XZ Utils breach, CI/CD pipeline vulnerabilities, SBOM limitations, and how Anthropic's Claude Opus 4 model accelerates vulnerability discovery at machine speed.

Key Questions Answered

  • Build from source to eliminate malware classes: Constructing packages directly from source code — rather than pulling pre-built artifacts from public registries like PyPI or npm — eliminates 98–99% of the attack vectors used in recent malware campaigns. Chainguard's library product blocked every malware attack targeting its customers over the past several months using this approach.
  • Short-lived credentials are non-negotiable in CI/CD: Nearly every major supply chain attack, including TJ Actions and Shailood, succeeded by exfiltrating long-lived credentials from CI/CD pipelines. Chainguard built OktoSCS, a free public credential federation service for GitHub, that issues only short-lived tokens backed by a KMS system requiring security team approval to access the underlying secret.
  • SBOM coverage percentage matters more than SBOM existence: Mandatory SBOM requirements in frameworks like the EU Cyber Resilience Act are insufficient without specifying coverage depth, format, and resolution. An SBOM covering only 10% of files in a container image technically satisfies schema requirements. Chainguard's approach ensures every file traces back to a versioned package, achieving near-100% provenance coverage.
  • Patch at machine speed or face compounding risk from AI vulnerability discovery: Anthropic's Claude Opus 4 found 10–20x more CVEs in a recent Firefox release than prior tooling. The model chains multiple vulnerabilities together to identify exploits that single-flaw scanners miss. Organizations not already automating patch pipelines will face a backlog of newly discovered, weaponizable vulnerabilities within the next six to twelve months.
  • Behavioral scanning catches grayware that signature tools miss: Beyond known malware signatures, scanning for anomalous syscall patterns between package versions — such as a patch release suddenly opening new network connections — flags both compromised and "grayware" packages. Differential scanning between dot-one and dot-two releases detects unexpected behavioral changes before a malicious build is published.

Notable Moment

When Moore tested Anthropic's newly released Claude Opus 4 model on a security isolation tool he had been auditing, the model detected the security research intent and automatically downgraded itself to a less capable version — demonstrating that the safety controls Anthropic described in its launch announcement are actively functioning.

Know someone who'd find this useful?

Episode Transcript

Open source software underpins virtually every modern application. That ubiquity is a superpower for developers, but it is also an expanding attack surface. Software supply chain attacks were once rare but are now happening daily with malicious actors exploiting the trust developers' place in public registries, package managers, and CICD pipelines. Chainguard is a secure software supply chain platform. The company started with hardened container images and has expanded to cover domains including VMs, language libraries, GitHub actions, and agent skills. Matt Moore is a cofounder and CTO of ChainGuard and a veteran of Google's open source container and security infrastructure work. In this episode, Matt joins Gregor Van to discuss lessons from recent supply chain attacks, why CICD pipelines are now a primary attack surface, the challenge of meaningful software inventories, the EU Cyber Resilience Act, and what the arrival of Anthropic's Mythos model means for the pace of vulnerability discovery and the urgency of patching at machine speed. Gregor Vand is a security focused technologist, having previously been a CTO across cybersecurity, cyber insurance, and general software engineering companies. He is based in Singapore and can be found via his profile at van.hk or on LinkedIn. Hello and welcome to Software Engineering Daily. Today is a fun one where we get to talk to a person in a company again. So at the end of many episodes we say we'll be following along and that's exactly what we've been doing here. So very happy to have Matt Murr of Chainguard back with us. So yeah, welcome Matt. Thanks for having me. Yeah. So some of you may remember the episode we did probably around two years ago I think at this point, something like that. With Chainguard, everything talking about hardened containers, about security. So spoiler alert, a lot has happened over the last two years from that perspective. So I think it's gonna be super interesting to dive into how Chainguard has evolved with that and, like, how it's protecting things and evolved. But as usual, just in case anyone didn't catch that episode, just a very, like, TLDR of who is Matt Moore, how did you get to Chainguard? Yeah. I'm Matt. I'm one of the founders of Chainguard and the CTO. Chainguard, my cofounders and I, we all met over many years of collaboration at Google. And we collaborated on things across open source, the container space, the security space, the developer experience space. And we have been working on parts of these problems for over ten years together. But one of my cofounders and I had left Google briefly, and I was on a break barbecuing and playing video games, trying to figure out what I wanted to do next. And our CEO, Dan, was trying to recruit me back to Google. And I was like, I don't really want to go back to big tech just yet. And so I Uno reverse carded him and I was like, have you thought about starting …

Get the full transcript (10,710 words) + summary by email — free

One-time email with the complete transcript and AI summary of this episode. No account needed.

One email, no spam. We’ll also show you what SignalCast does.

Browse all Software Engineering Daily transcripts →

You just read a 3-minute summary of a 54-minute episode.

Get Software Engineering Daily summarized like this every Monday — plus up to 2 more podcasts, free.

Pick Your Podcasts — Free

Keep Reading

More from Software Engineering Daily

We summarize every new episode. Want them in your inbox?

Similar Episodes

Related episodes from other podcasts

Explore Related Topics

This podcast is featured in Best Cybersecurity Podcasts (2026) — ranked and reviewed with AI summaries.

Read this week's AI & Machine Learning Podcast Insights — cross-podcast analysis updated weekly.

You're clearly into Software Engineering Daily.

Every Monday, we deliver AI summaries of the latest episodes from Software Engineering Daily and 192+ other podcasts. Free for one show.

Start My Monday Digest

No credit card · Unsubscribe anytime