What are Malicious Packages? How Do They Work?
Deceptive βVibrancedβ npm Package Discovered Masquerading as Popular βColorsβ Package
Cybercriminals targeted users of packages with a total of 1.5 billion weekly downloads on npm
Single Author Uploaded 168 Packages to npm as Part of a Massive Dependency Confusion Attack
New Typosquatting Attack on npm Package βcolorsβ Using Cross language Technique Explained