Dependency Sprawl: The Transitive Dependencies That Own Your Attack Surface
When a dependency gets exploited, it is almost never the one in your package.json. It is the one three layers under it, maintained by someone whose name you have never seen, pulled in as a side effect