vulns.co
/
GKData.io MCP

Back to Playbooks

Dependency Confusion & Supply Chain

Discover internal package names and (with authorization) demonstrate how a public look-alike could be pulled into builds.

Tags: supply-chain, npm, pypi, ci

Level: advanced

Method

  1. Harvest internal names

    Scrape package.json, requirements.txt, .npmrc, lockfiles, and JS bundles for internal/private package names.

    cat jsfiles.txt | jsluice urls | grep -i 'internal\|@corp'

    Tools: jsluice, trufflehog, gitleaks

  2. Check registry gaps

    See whether those names are unclaimed on public npm/PyPI - an unclaimed internal name is the confusion vector.

    npm view <internal-pkg> 2>/dev/null || echo unclaimed
  3. Prove impact safely

    Only within scope and program rules: a benign PoC that phones home (no data exfil) demonstrates resolution without harm. Never publish malicious code.

    Tools: interactsh

Field notes

  • Scoped packages (@org/pkg) with an unclaimed scope are prime candidates.
  • This is high-impact and high-sensitivity - get explicit authorization first.

References