The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name
Original research and analysis on malicious packages in open source registries β attack techniques like typosquatting, plus detection and defense.
Deceptive βVibrancedβ npm Package Discovered Masquerading as Popular βColorsβ Package
Cybercriminals targeted users of packages with a total of 1.5 billion weekly downloads on npm
Single Author Uploaded 168 Packages to npm as Part of a Massive Dependency Confusion Attack