Dependency confusion exploits naming and resolution
The attack needs no vulnerability. It needs your build tool to look in two places and choose wrong.
Publish a package with the same name as one of your internal ones to a public registry, and a resolver configured to check public sources first will fetch theirs. The fix is in configuration rather than vigilance: control where names resolve from, and scope internal packages so they cannot be claimed by anybody else.
More on Software supply chain
- A trusted build can faithfully ship malicious sourceThe oven never reads the recipe
- Typosquatting attacks developer attentionThe eye test you take at 2am
- Lockfiles improve repeatability, not eternal safetyAlways the same tin
- Transitive dependencies enlarge unseen trustOne handshake, a hundred guests
- Maintainer compromise can use the normal release channelIt came by the usual van
- Build secrets should not become build artefactsDeleted on top, still underneath
