Typosquatting and Other Attacks Against Open Source Dependencies
In November of 2018 a malicious Javascript package was identified and subsequently removed from the NPM ecosystem. A nefarious modification was introduced into this package, flatmap-stream, which was then added as a direct dependency to the