npm
The React Framework
Public repositories of contributors | 1,490 |
Followers of contributors | 105,000 |
Repository forks | 27,000 |
Open issues | 3,000 |
Repository watchers | 1,450 |
Number of contributors | 3,520 |
Repository stars | 127,000 |
Package has a provenance record signed with Sigstore, confirming its source of origin.
Typosquatting is the risk of installing a malicious package that uses a name similar to a legitimate one.
Starjacking can mislead users into trusting a package, hiding malicious code behind inflated popularity.