Togoder security

Glossary

Supply-chain security glossary

Plain definitions of the attacks and tools behind open-source dependency security, with real incidents and the commands that defend against them.

Dependency confusion

Dependency confusion (also called a substitution attack) is publishing a package to a public registry under the same name as a company's internal package, so that a misconfigured package manager installs the public, attacker-controlled version instead.

Install scripts (postinstall)

Install scripts are commands a package declares in package.json (preinstall, install, postinstall) that npm runs automatically during installation, with the installing user's permissions, for every package in the dependency tree.

Lockfile

A lockfile (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock, poetry.lock, Cargo.lock and others) records the exact resolved version, download URL and integrity hash of every direct and transitive dependency, so installs are reproducible.

Maintainer account takeover

A maintainer account takeover is when an attacker gains control of a package maintainer's registry account or publish token, through phishing, password reuse or a leaked token, and uses it to publish a malicious version of a trusted package.

Protestware

Protestware is open-source software that its own maintainer deliberately changes to make a protest or political statement, ranging from printing a message to breaking the package or damaging files on certain machines.

SBOM (software bill of materials)

An SBOM (software bill of materials) is a machine-readable inventory of the components in a piece of software, including each open-source package, its version, supplier and license, usually in the SPDX or CycloneDX format.

Slopsquatting

Slopsquatting is registering package names that AI models hallucinate, so that when a coding assistant (or a developer copying its answer) runs the install command, the attacker's package is what gets installed.

Software composition analysis (SCA)

Software composition analysis (SCA) identifies the open-source components an application uses, usually from lockfiles or manifests, and matches them against databases of known vulnerabilities (CVEs and advisories) and license terms.

Software supply chain attack

A software supply chain attack compromises something a target trusts and installs, such as an open-source dependency, a build tool, a CI action or a vendor update, so that malicious code reaches every downstream user without attacking them directly.

Typosquatting

Typosquatting is publishing a malicious package (or registering a domain) under a name that is one slip of the keyboard away from a popular one, so that people who mistype the name install the attacker's code instead.

Go deeper

Step-by-step guides to checking packages, locking down install scripts and scanning lockfiles in CI.