May Microsoft alert dropped 45 malicious npm packages targeting dev environments. 33 in the first wave, 12 more the next day. Dependency confusion. Same attack Alex Birsan pulled off back in 2021.
Still works. Still gets past everything.
Not because it's clever. Because of what your tools actually do.
SCA scanner sees a new package? It's comparing against a database of known bad stuff. A brand new public impostor isn't in that database yet, there's nothing to match against, gets flagged clean, installs without a second look.
Lockfile pinned to the right version? Fine, until someone adds a new dependency, or pins to latest, or a fresh install runs before the lockfile gets committed. That's when the resolver sees your private package name sitting on both a private and public registry, compares versions, picks the highest. Attacker published 9.9.9. Lockfile writes it down as legit on the next run like nothing happened.
Post-build scanning is just forensics at that point. Package already fetched. Install hooks already ran, with whatever access that grants inside the pipeline. You're not catching the attack, you're documenting it after the fact.
What actually stops it: Claim your internal package names on public registries first. Even empty placeholders work. An attacker can't register a name you already own.
Scope your internal packages,
SOCIAL SHARE CARD GENERATOR