Popular Is Not the Same as Safe
Look-alike package names, unexpected dependency changes and install scripts can bring malware into builds.
Illustrative scenario
How It Looks in Real Life
A pull request adds a package called reqeusts-helper. The name looks familiar, the README is copied from a real project, and it has an install script.
Understand it
How the Attack Works
Attackers publish packages with names close to real ones, or compromise maintainers of existing packages. Install scripts run on developer machines and CI with access to tokens and source code.
Red flags
Warning Signs
- Misspelled or slightly altered names of well-known packages.
- New dependencies added without explanation in a pull request.
- Install or postinstall scripts in a package that should not need them.
Safer habits
What to Do Instead
- 1Verify the exact package name, publisher and repository link before installing.
- 2Commit lockfiles and review dependency diffs like code.
- 3Restrict install scripts in CI where possible and use dependency scanning.
Response playbook
Already Interacted?
For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.
If you: installed software or ran a command
- 1Disconnect the device from the network (Wi-Fi off or cable out) but leave it powered on.
- 2Report to IT or security and describe exactly what you ran or installed.
- 3Do not delete files, wipe the device or run cleanup tools yourself; evidence helps the investigation.
- 4From a different, trusted device, change passwords for accounts used on the affected machine.
If you: exposed a token, key or secret
- 1Revoke or rotate the exposed secret at the provider first; deleting the commit or message is not enough.
- 2Report it to the security team with where and when it was exposed. Never paste the secret itself into the report.
- 3Review provider logs for use of the key after the exposure time.
Knowledge Check
What Would You Do?
Which signal proves a package is safe?
Fictional example for learning. Not a test score or certification.
Sources
Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.
Make Safe Habits Part of Your Culture
Plain-language awareness sessions for everyday staff, developers and business teams.