npm Bin Entry Harvesting: A Dependency Confusion Blind Spot
21 malicious npm packages targeted Google by squatting CLI binary names from scoped packages, not package names. The technique exploits a structural gap that standard dependency confusion defenses do...