Official MASTR logo MASTR Support the work
Contents
← Wiki home

Scam patterns

Poisoned software dependencies

A familiar or mistyped package adds key theft or transaction manipulation to a build.

Reference note · Sources below

Research articles and reference entries are published in English. Navigation is available in seven languages.

People & projects

In this article
  1. Overview
  2. Why it matters
  3. What to check
  4. Sources

Overview

A familiar or mistyped package adds key theft or transaction manipulation to a build.

Why it matters

Users are reached through a developer's supply chain.

What to check

Pin versions, inspect lockfile changes and preserve package hashes and provenance.

Sources

Related reading

MASTR

Support independent research

The investigations, original evidence and guides here are free to read. Voluntary donations help fund the research and keep MASTR’s tools available.

Open wallet