Posts on dependency-confusion
4 posts on dependency-confusion. Notes from public sources and my own test lab.
Betrayal of the Dependencies: The Art of Supply Chain Attacks and Defense
Ever wondered how a single typo in your package.json could compromise your entire infrastructure? Let's dive into the world of Software Supply Chain security and learn how to defend your fortress from the inside out.
When the Foundations Crumble: Software Supply Chain and 'Dependency Hell'
Think you're safe behind your firewall? Think again. The real threat might be that 'npm install' you just ran. Let's dive into the messy world of Software Supply Chain attacks and how they turn your trust against you.
Trusting Your Package Manager? Feeding a Trojan Horse in the Supply Chain
Think your CI/CD pipeline is safe because of a few SCA scans? Think again. We’re diving into the blind spots of package managers, from malicious logic to dependency confusion.
When Your Safety Net Becomes a Trap: How Library Dependencies Betray You
Ever wonder who actually wrote the 100,000 lines of code running in your 'small' microservice? Let's talk about the fragility of the software supply chain and how Red Teamers exploit it.