Incidentnpm Aliasing Led to Phantom Dependencies
What Happened Security researchers Mario Stathako and colleagues found that npm s package aliasing feature—intended to let developers install packages under different names—creates a new risk for depe














