Dependency confusion exploits naming and resolution

The attack needs no vulnerability. It needs your build tool to look in two places and choose wrong.

Publish a package with the same name as one of your internal ones to a public registry, and a resolver configured to check public sources first will fetch theirs. The fix is in configuration rather than vigilance: control where names resolve from, and scope internal packages so they cannot be claimed by anybody else.

More on Software supply chain