scanner
scanner copied to clipboard
Malicious / Dangerous spec resolver to custom URL
Custom spec resolver can be used to fake a package name (such as axios in the following example)
https://snyk.io/blog/exploring-extensions-of-dependency-confusion-attacks-via-npm-package-aliasing/