Dependency Confusion & Supply Chain
Discover internal package names and (with authorization) demonstrate how a public look-alike could be pulled into builds.
Tags: supply-chain, npm, pypi, ci
Level: advanced
Method
Harvest internal names
Scrape package.json, requirements.txt, .npmrc, lockfiles, and JS bundles for internal/private package names.
cat jsfiles.txt | jsluice urls | grep -i 'internal\|@corp'Tools: jsluice, trufflehog, gitleaks
Check registry gaps
See whether those names are unclaimed on public npm/PyPI - an unclaimed internal name is the confusion vector.
npm view <internal-pkg> 2>/dev/null || echo unclaimedProve impact safely
Only within scope and program rules: a benign PoC that phones home (no data exfil) demonstrates resolution without harm. Never publish malicious code.
Tools: interactsh
Field notes
- Scoped packages (@org/pkg) with an unclaimed scope are prime candidates.
- This is high-impact and high-sensitivity - get explicit authorization first.