Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

https://github.com/andyrichardson/exploiting-npm-downloads


https://github.com/andyrichardson/exploiting-npm-downloads

Last synced: 16 days ago
JSON representation

Awesome Lists containing this project

README

        

---

**Disclaimer:** I've documented this to bring light to how easily exploitable download statistics are. However, I strongly advise that you don't do this as it is both dishonest an unnecessary drain on NPM Inc's resources.

---

# About

A demonstration of how NPM _download_ and _popularity_ statistics can be easily exploited.

Check out the [blog post here](https://dev.to/andyrichardsonn/how-i-exploited-npm-downloads-and-why-you-shouldn-t-trust-them-4bme).

## Usage

To deploy to AWS

> Seriously, don't do this other than for experimentation purposes

```
cd terraform
terraform init
terraform apply
```

## The result

Screenshot 2021-03-08 at 21 02 07

_Blue line was used as the target package and has 0 users_.