## TL;DR

Fix: npm uninstall biome, install the correct scoped package as a dev dependency, reinstall node_modules, then run socket fix and socket optimize so the Socket Registry substitutes a hardened replacement.

## Steps

1. Per the Socket.dev case study: always verify the exact package name - typosquats and lookalikes drag in vulnerable transitives.

## When to use

You are seeing this: Per the Socket.dev case study: always verify the exact package name - typosquats and lookalikes drag in vulnerable transitives. Use this skill when you run into "Socket.dev critical CVEs via the wrong package name: biome is not @biomejs/biome".

## When not to use

If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.

## Versions

Versions mentioned in the source: lodash 3.10.1, biome 0.3.3. If you are on something much newer or older, the details may have shifted.

## Why this happens

The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.
