Dependency confusion

If a build system can find a package name in more than one place, the attacker picks the place you did not mean.

Publish something with your internal package's name to a public registry, and a resolver that checks public sources first will fetch theirs. Nothing was compromised; the naming and resolution rules did the work. It is fixed by controlling resolution order and by scoping internal names, not by vigilance.

Checked against the primary source.

More on Application security