Web Hack List

Later archive addition

Why npm lockfiles can be a security blindspot for injecting malicious modules

The article shows how a malicious pull request can hide a dependency source replacement inside a large yarn.lock or package-lock.json diff, causing installs to fetch and run an attacker-controlled module. It recommends automated lockfile policies, trusted HTTPS registries, tighter review ownership, and avoiding lockfiles for published libraries.

Record

Researcher
Liran Tal
Published by
Snyk
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Liran Tal, first published at the original source. Preserved copies are kept so the citation survives its host.