Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. CI/CD Attacks
  3. Why npm lockfiles can be a security blindspot for injecting malicious modules

Why npm lockfiles can be a security blindspot for injecting malicious modules

Visit WebsiteGitHubGitHub
0 stars0 forks0 contributors

Overview

Malicious code can be injected into npm projects via lockfiles (package-lock.json or yarn.lock) because these large, machine-generated files are rarely reviewed thoroughly

Quick Stats

Stars0
Forks0
Contributors0
Open Issues0
Last commit
Created

Links & Resources

Website

Included in

CI/CD Attacks578

Related Projects

PR sneakingPR sneaking

A repository demonstrating how you can sneak malicious code into Github PRs

Stars11
Forks1
Last commit9 years ago
Remove evidence of malicious pull requests on GitHubRemove evidence of malicious pull requests on GitHub

Changing account's email to block-listed domain, automatically bans the account

Stars0
Forks0
Last commit
GitHub comments abused to push malware via Microsoft repo URLsGitHub comments abused to push malware via Microsoft repo URLs

Hidden GitHub comment link

Stars0
Forks0
Last commit
How a Single Vulnerability Can Bring Down the JavaScript EcosystemHow a Single Vulnerability Can Bring Down the JavaScript Ecosystem

Cache poisoning attack on the NPM registry rendering packages unavailable

Stars0
Forks0
Last commit
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub