
← DevSec Station21 mei · 8 min
Malicious Dependencies Aren’t an Accident
Malicious Dependencies Aren’t an Accident
Malicious dependencies are not accidents. They are often intentionally designed to look trustworthy so developers install them without hesitation. In this episode of DevSec Station, Tanya Janca explains how attackers use typosquatting, dependency confusion, fake packages, and even AI-generated recommendations to compromise developer environments and steal credentials. This episode is sponsored by Maze. You’ll learn: • how malicious packages trick developers • why dependency attacks work...