Possessed by Packages - Is Your JavaScript Haunted by Chris DeMars
This guy takes his slides very seriously
Should be a masterclass in creating slides honestly. Gave shoutouts to the conference itself and the sponsors
DeveloperCommunity
The haunting
Infestation
Obsession
Oppression
Possession
The signs
The fixes
npm ls
For a list of dependencies in the code
npm ls -all for everything...
Typosquatting - an attacker registers a package that is off by a letter or has too many letters. crossenv was a good one. Copy and paste the command from the documentation
Dependency Confusion - nearly 49% of orgs are exposed to risks of dependency confusion attack
Configure your .npmrc file to only pull from a private registry and CI/CD platform.