依赖混淆检测

原名:detecting-dependency-confusion

通过枚举可占用的内部包名并强制源限制,检测并防止 npm、PyPI 和 Maven 中的依赖混淆攻击。适用于供应链安全项目入职、锁文件审计或内部包名泄露事件后的响应。

分类
开发提效
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
2
收藏
0
发布
2026-08-18
更新
2026-09-07
TRACE 评分
3.4 / 5

内容概览

Legal Notice: This skill is for authorized security testing, defensive engineering, and educational purposes only. Registering or claiming package namespaces you do not own, or testing build pipelines without written authorization, may be illegal and may violate the terms of service of public registries. Only run namespace-claiming or resolution-testing activities against names and infrastructure you control or are explicitly authorized to assess. Dependency confusion (also called a substitution or namespace-shadowing attack) was popularized by Alex Birsan in 2021 when he forced malicious code into the internal build systems of Apple, Microsoft, PayPal, and dozens of others. The root cause is that many package managers, when configured to resolve from both an internal/private registry and a public one, will prefer whichever copy has the higher version number rather than honoring the sour…

查看 SKILL 详情