Your Third-Party Code Is Someone Else's Backdoor
That npm install you ran six months ago didn't just pull in one package — it pulled in dozens you've never heard of, maintained by people you've never vetted. Dependency risk isn't about the libraries you know. It's about the ones you've completely forgotten.