The Largest NPM Supply Chain Attack Ever and How to Defend Against It
Analysis of major NPM supply chain attacks and practical defense strategies for protecting your applications from malicious packages and dependencies.
Mohammad‑Ali A'râbi is a Senior Backend Engineer at JobRad, Docker Captain, Snyk Ambassador, and founder of the Black Forest Docker community. Author of Docker and Kubernetes Security (published October 2025) and upcoming fiction novel Black Forest Shadow. He speaks at developer conferences and organizes meetups across Europe.
He is a Senior Backend Engineer at JobRad, a Docker Captain, Snyk Ambassador, and a CNCF community organizer in Freiburg. He founded the Docker Black Forest community and organizes Cloud Native Freiburg meetups, having organized 25+ events with 200+ community members. His background is in mathematics and logic; he studied Pure Mathematics and researched logic and programming language theory before moving full‑time into software engineering.
Watch my conference talk from Jfokus on secure Java containerization with SBOMs and attestations.
Containerizing applications is easy. Containerizing them securely is not.
Want to see more technical content?
Founder and organizer of Docker Black Forest and Cloud Native Freiburg communities, bringing together developers, DevOps engineers, and tech enthusiasts in the Baden-Württemberg region.
Founded 2022 • Freiburg, Germany
Quarterly meetups focusing on Docker, containers, and DevOps practices. Regular workshops, hands-on sessions, and expert talks covering everything from basic containerization to advanced orchestration.
Co-organizer • CNCF Chapter
Part of the global Cloud Native Computing Foundation community. Hosting events on Kubernetes, DevOps, observability, and cloud native security practices.
Browse all past and upcoming meetups, presentations, and workshop materials.
Visit Dockburg.comComplete list of speaking engagements, workshops, and community activities. From major conferences to local meetups.
Comprehensive guides on container security, DevOps best practices, and software supply chain security.
October 2025 • Published
A practitioner's guide to securing container images, build processes, and supply chains. From SBOMs and attestations to runtime hardening and policy enforcement.
2026 • To be published
A gripping tale set in the mystical Black Forest region, weaving together elements of mystery, technology, and local folklore in this upcoming fiction work.
Join the newsletter for updates on this upcoming book.
In-depth articles on container security, DevOps practices, and software development insights.
Analysis of major NPM supply chain attacks and practical defense strategies for protecting your applications from malicious packages and dependencies.
Comprehensive guide to securely containerizing Java applications, covering best practices for image building, runtime security, and vulnerability management.
Step-by-step guide to containerizing a full-stack MEAN application, covering MongoDB, Express, Angular, and Node.js deployment with Docker.
A detailed writeup of the "Potty Training" challenge from Fetch the Flag CTF 2022, exploring container security vulnerabilities and exploitation techniques.
Regular technical content on container security, DevOps automation, and software engineering best practices.
Want a talk, workshop, or collaboration? Reach out by email or DM.
Get updates about Docker security and the Docker Security book.