Sébastien Lorber, a maintainer of the Docusaurus project, discovered suspicious npm packages like `string-width-cjs` through a pull request. The investigation unveiled that these packages, which are empty and have anonymous authors, could potentially be part of a supply chain security risk in the npm ecosystem. Tools like lockfile-lint were used to identify these packages. The findings raise concerns about npm lockfile security and dependency confusion, emphasizing the importance of vigilance and security practices in managing open-source dependencies.

8m read timeFrom snyk.io
Post cover image
Table of contents
Finding suspicious behavior in npm lockfiles concerning malicious modulesHigh-alert: popular packages look-alikes on npmFurther thoughts on suspicious npm package findingsSecure your code as you develop

Sort: