Web Security

Security concepts guides

Developer-focused explanations of race conditions, dependency confusion, trivial packages, and package hijacking.

What these guides cover

These guides explain supply-chain and concurrency failures that show up in application code and in the package graph, not only in a network scan. A race condition is a TOCTOU gap between a check and a write. Dependency confusion is a public package that wins over a private name. A trivial package is a one-liner that an ecosystem later cannot delete safely. Package hijacking is a trusted name that starts serving someone else's code. Each article defines the failure, shows how it is executed, and lists the controls that close it.

Risks

  • Check-then-act gaps on coupons, balances, and inventory
  • Internal package names resolved from a public registry
  • One-line dependencies that become unmaintained attack surface
  • Compromised maintainer accounts, expired domains, and repo jacking

Control priorities

  • Atomic writes, unique constraints, and idempotency keys
  • Scoped registries, lockfiles, and private-package prefixes
  • Native language APIs instead of trivial packages
  • 2FA, domain control, and release automation for publishes

Recommended reading order

Read the four guides as a cluster. Start with the failure that matches your incident: race conditions for concurrent writes, dependency confusion for private registries, trivial packages for dependency bloat, and package hijacking for a compromised publish.

Guides in this collection

Security concepts

What is a race condition attack?

Force two requests through the same check-then-act window so a one-time coupon or token is used twice.

Read guide
Security concepts

What is a dependency confusion attack?

A public package that shares an internal name installs instead — reserve your npm scope and pin it in .npmrc.

Read guide
Security concepts

What is a trivial package?

A trivial package is a short dependency you could write yourself. Prefer natives such as padStart over tiny npm helpers.

Read guide
Security concepts

What is package hijacking?

When someone else can publish a package you trust, or serve a replacement at a URL you pin — accounts, domains, Polyfill.io.

Read guide