DEV Community

Cover image for The most dangerous code in your app is the code you didn't write
Ksatria Bintang Samudra
Ksatria Bintang Samudra

Posted on

The most dangerous code in your app is the code you didn't write

Here is a thing nobody tells you on your first day as a developer.

You type npm install, hit enter, and in about four seconds you just invited a few hundred strangers to run code on your machine and, eventually, on your users' machines too. You read none of it. Nobody does.

Modern software is not written. It is assembled. Your app is maybe 10 percent your code and 90 percent other people's, pulled from the internet by name, on trust. And trust, as any security person will tell you, is the whole attack surface.

I come from penetration testing, and I build AI-native now. This is the risk that scares me most, precisely because it is invisible.

When a dependency turns on you

event-stream, 2018. A popular npm package, millions of downloads a week. The tired original maintainer handed it to a friendly stranger who offered to help. That stranger quietly added code that stole cryptocurrency from apps depending on it. Nobody noticed for months.

colors and faker, 2022. Two tiny packages sitting quietly under thousands of projects. Their own maintainer sabotaged them on purpose, pushed an infinite loop, and broke apps around the world overnight. No hacker needed. Just one person with commit access and a bad day.

xz-utils, 2024. This one should have been a catastrophe. Over nearly three years, someone patiently social-engineered their way into becoming a trusted maintainer of a compression library that ships inside basically every Linux server on the planet, then slipped in a backdoor targeting SSH. It was caught almost by accident, by one engineer who noticed his login felt a fraction of a second too slow. That tiny delay stood between us and a backdoor in half the internet.

SolarWinds, 2020. Attackers compromised the build system of a trusted IT vendor and shipped a backdoor inside a normal software update. Around 18,000 organizations installed it themselves, including governments and Fortune 500s. They did everything right and still got owned, because the poison came from a source they trusted.

Lines of code on a screen

Now add AI to the fire

Here is the 2024 twist, and it hits close to home for me as an AI-native dev.

AI coding assistants sometimes recommend packages that do not exist. They confidently tell you to install something, a hallucinated name, and you paste it without blinking. Attackers figured this out. They watch for the names AI tends to invent, register those exact packages, and fill them with malware. You asked an AI for help, and it sent you to a trap someone pre-loaded.

They call it slopsquatting. I call it a reminder that the model does not know, it predicts, and your install command does not care about the difference.

How I sleep at night

You cannot read every line of every dependency. But you can stop being an easy, trusting target:

  • Use a lockfile and commit it. Know exactly what version of what shipped.
  • Install less. Every dependency is a door. Do you really need a 40-line package for something you can write in 5?
  • Verify the name before you install, especially from an AI. Real downloads, a real repo, a real history. If an AI suggests a package, confirm it actually exists and is the one you think it is.
  • Run an audit. npm audit, pip-audit, Dependabot. Free, automatic, and they catch a shocking amount.
  • Pin and review updates. A dependency bump is a code change from a stranger. Treat it like one.

The quiet truth

The breach that gets you probably will not be some elite zero-day aimed at you personally. It will be a line of code you never wrote, in a package you never read, that you trusted because everyone else did too.

You are not just shipping your code. You are shipping everyone's. So know whose shoulders you are standing on, because some of them are not who they say they are.

Read the label before you swallow the pill.


I am Ksatria Bintang Samudra, an AI-native full-stack engineer with a penetration-testing background and a deep interest in digital forensics, open to remote work worldwide. More of what I build at ksatriabintangsamudra.com.

Top comments (0)