Scam patterns
Compromised package maintainers
An attacker publishes a malicious version through a legitimate package account.
Research articles and reference entries are published in English. Navigation is available in seven languages.
In this article
Overview
An attacker publishes a malicious version through a legitimate package account.
Why it matters
Normal publisher reputation and automated upgrades spread the payload.
What to check
Require signed, reproducible builds and record exact version and publication time.