Official MASTR logo MASTR Support the work
Contents
← Wiki home

Scam patterns

Compromised package maintainers

An attacker publishes a malicious version through a legitimate package account.

Reference note · Sources below

Research articles and reference entries are published in English. Navigation is available in seven languages.

In this article
  1. Overview
  2. Why it matters
  3. What to check
  4. Sources

Overview

An attacker publishes a malicious version through a legitimate package account.

Why it matters

Normal publisher reputation and automated upgrades spread the payload.

What to check

Require signed, reproducible builds and record exact version and publication time.

Sources

Related reading

MASTR

Support independent research

The investigations, original evidence and guides here are free to read. Voluntary donations help fund the research and keep MASTR’s tools available.

Open wallet