Malicious packages in NPM evade dependency detection through invisible URL links
csoonline.com
csoonline.com
With all the faults of npm, I fail to see that as npm fault. That sounds honestly like a security system fault. Why would an audit tool ignore a clearly defined dependency?