NPM Plagued With ‘Manifest Confusion’ Malware-Hiding WeaknessBy rooter / June 28, 2023 The popular package manager for software developers has been vulnerable to this attack vector for a while, and negligent in fixing the problem, according to a former employee.