> A large number of corrupted packages use names related to game cheats, free resources, and social media platforms, such as "free-tiktok-followers" and "free-xbox-codes," to entice users to click the links and direct them to multiple well-designed phishing webpages.
The same problem exists on Docker Hub, e.g.
https://hub.docker.com/r/neyprivedpu1972/windows-7-7264-down...
What makes me wonder is why it’s always NPM that’s hit with these kind of things, and not, say, Maven? Arguably the attack surface of Maven is much larger and intrusive (lots of enterprises), but the mechanisms of package distribution are completely different. There are a shitload of scans and sanity checks happening when you push a package to a Maven repo such as Sonatype, which I don’t see as much with NPM (and also Pypi for that matter)
(fwiw, I am responsible for package distribution of all APIs of a reasonably popular timeseries database)
Along with all the scanning and what not, I think that’s the biggest reason you see attacks primarily on npm, PyPi, and to an extent Ruby Gems.