Dependency Attacks: How One Package Can Burn Your App Typosquatting, compromised maintainers, and how to defend.