DevSec Station

← DevSec Station21 mei · 8 min

Malicious Dependencies Aren’t an Accident

Malicious Dependencies Aren’t an Accident21 mei8 min

Malicious dependencies are not accidents. They are often intentionally designed to look trustworthy so developers install them without hesitation. In this episode of DevSec Station, Tanya Janca explains how attackers use typosquatting, dependency confusion, fake packages, and even AI-generated recommendations to compromise developer environments and steal credentials. This episode is sponsored by Maze. You’ll learn: • how malicious packages trick developers • why dependency attacks work...