What is a race condition attack?
Force two requests through the same check-then-act window so a one-time coupon or token is used twice.
Read guideWeb Security
Developer-focused explanations of race conditions, dependency confusion, trivial packages, and package hijacking.
These guides explain supply-chain and concurrency failures that show up in application code and in the package graph, not only in a network scan. A race condition is a TOCTOU gap between a check and a write. Dependency confusion is a public package that wins over a private name. A trivial package is a one-liner that an ecosystem later cannot delete safely. Package hijacking is a trusted name that starts serving someone else's code. Each article defines the failure, shows how it is executed, and lists the controls that close it.
Read the four guides as a cluster. Start with the failure that matches your incident: race conditions for concurrent writes, dependency confusion for private registries, trivial packages for dependency bloat, and package hijacking for a compromised publish.
Force two requests through the same check-then-act window so a one-time coupon or token is used twice.
Read guideA public package that shares an internal name installs instead — reserve your npm scope and pin it in .npmrc.
Read guideA trivial package is a short dependency you could write yourself. Prefer natives such as padStart over tiny npm helpers.
Read guideWhen someone else can publish a package you trust, or serve a replacement at a URL you pin — accounts, domains, Polyfill.io.
Read guide