Supply chain security is evolving at a terrifying pace. In this episode of The Security Disclosure, Roeland Delrue (COO and co-founder of Aikido Security) breaks down why attackers have shifted their crosshairs from cloud infrastructure directly onto the individual developer's machine. We dive deep into how malicious JavaScript packages, VS Code extensions, and Chrome extensions manage to slip past traditional endpoint software like CrowdStrike or McAfee, and discuss the practical, counterintuitive steps security teams can take right now to protect themselves. Roeland also shares a surprisingly candid take on why open-source marketplaces like NPM and PyPI need to step up, why giving threat actors "oxygen" on social media does more harm than good, and plays a brutal round of tech "Would You Rather." Check out Aikido Security: https://aikido.dev 00:00:00 Introduction to Roeland Delrue and Aikido Security 00:01:20 Why Aikido Security Was Founded 00:02:47 The Exploding Rise of Supply Chain Attacks 00:05:04 Is AI Fueling the Surge in Malicious Packages? 00:06:24 The Shift From Cloud Targets to the Developer Machine 00:07:21 Why Traditional Endpoint Scanners Fail to Detect Malicious JavaScript 00:10:44 How Minimum Package Age Restricts 98% of Malware 00:13:06 Solving Supply Chain Security at the Root Source 00:14:49 How Malware Detection Differs From Standard Vulnerability Scanning 00:16:50 Dynamic Analysis and Controlled Malware Detonation 00:18:37 Why We Need to Stop Giving Threat Actors Media Attention 00:20:51 Can Marketplaces Mimic the Apple App Store Review Process? 00:24:49 Would You Rather