We’re running the Supply Chain Security Village at c0c0n 2026 — 9–10 October, Kochi, IndiaEvent page

About the village

Supply Chain Security Village

An open, community-run space for the people who find, exploit, and defend the software supply chain — talks, live demos, hands-on CTFs, and the researchers behind them.

Supply Chain Security Village exists because supply chain security is one of the most critical — and most underserved — areas in cybersecurity today.

Most security training focuses on application vulnerabilities. But the real risk is upstream — in the dependencies developers pull without thinking, the build systems that run with implicit trust, and the CI/CD pipelines that deploy code with no verification of what changed along the way. These are the entry points attackers increasingly target, and there's no dedicated platform teaching practitioners how to defend against them.

The same pattern shows up well beyond code — in logistics and shipping, in procurement and third-party suppliers, in the hardware and firmware that arrive from three tiers down. Different vocabulary, same failure: trusting an upstream nobody verified. Our hands-on work is mostly on the software side, because that's where our experience is — but the people who move goods, parts, and components face this too, and they're welcome here.

We built this to fill that gap. No sponsors. No sales pitch. Just a community of security practitioners, developers, and researchers who believe that understanding supply chain threats requires hands-on practice — not slide decks.

Community-Driven

Every challenge, talk, and resource is created by practitioners. The platform grows because the community grows.

Open to All

All skill levels welcome. No gatekeeping, no paywalls. The supply chain is everyone's problem — and everyone's to defend.

Developers & DevOps

Understand how the tools you use daily — package managers, CI systems, container registries — become attack vectors. Build with security in the pipeline, not as an afterthought.

Security Researchers

Sharpen your skills on real supply chain attack patterns. Dependency confusion, build poisoning, backdoor analysis — the new frontier of offensive security.

AppSec & Red Teams

Test and defend the supply chain. Learn to assess third-party risk, audit SBOMs, and find the gaps that traditional application pentests miss.

OSS Maintainers

Your project is someone else's dependency. Learn the patterns attackers use to compromise open-source packages and how to protect the software others rely on.

Students & Newcomers

No prior supply chain security experience needed. Start from the fundamentals and work your way up through real challenges — not textbooks.

Leadership

Leadership Team

Sunil Yadav

Sunil Yadav

Village Lead

Anant Shrivastava

Anant Shrivastava

Advisor

Cyfinoid Research

We're growing — Looking for challenge designers, speakers, mentors, and volunteers. Whether you work on software, hardware, logistics, or the warehouse floor, if you care about how things get from source to destination safely, there's a place for you here.

Sponsors & Partners

Powered by community goodwill

Supply Chain Security Village runs on volunteer time and community support. We're looking for partners who share our mission.

Become a sponsor

Help us keep Supply Chain Security Village free and open. Sponsorships fund event infrastructure, prizes, and community grants.

Get in touch

Get involved

Ready to Find the Weak Link?

Speak. Design challenges. Mentor newcomers. Volunteer. Or just show up and hack. The supply chain needs more people paying attention.

Get Involved