Now I am curious at whether these ZIP confusion attacks are mitigated at other registries that use ZIPs? Are there any such?
Apart from Python Wheels, the other popular ecosystems using zip files are Java jar files, and NuGet. Of these Java is the most interesting as there a few JDKs commonly in use. But I’m also interested in various security scanners that are built in other languages that can be fooled.
(Search results for `npm package format` are entirely not useful for figuring out what an NPM package actually consists of, beyond containing a `package.json` file. `pypi package format` results look wildly different; the first result I get is https://packaging.python.org/en/latest/discussions/package-f... which is quite comprehensive about the exact information I want — disregarding for a moment the fact that I already know this stuff ;) The NPM search results, for me, start with a Geeks4Geeks tutorial on creating a package. Is there even anything analogous to the Python Packaging Authority — misunderstood and not-actually-authoritative as it is — for NPM?)