0x48 - Finding NPM Dependency Confusion
0x48 - Finding NPM Dependency Confusion
Pentest Tips & Tricks
A01 - Broken Access Control
A01 - Broken Access Control
A02 - Cryptographic Failures
A02 - Cryptographic Failures
A03 - Injection Attacks
A03 - Injection Attacks
A04 – Insecure Design
A04 – Insecure Design
A05 – Security Misconfiguration
A05 – Security Misconfiguration
A06 – Vulnerable Components
A06 – Vulnerable Components
A07 – Identification and Authentication Failures
A07 – Identification and Authentication Failures
Recon & Attack Surface
Recon & Attack Surface
Tooling & Automation
Tooling & Automation
Creative, Strategic, and Mindset
Creative, Strategic, and Mindset
Bug Bounty $$$
Bug Bounty $$$
AI/ML/LLM/MCP
AI/ML/LLM/MCP
Latest Tips & Tricks
Latest Tips & Tricks
Did you know you can compromise an application without even sending one HTTP request to it?
Dependency confusion occurs when a malicious actor publishes a package to a public registry (like npm) with the same name as an internal package used by an organization
How to do it
Browse the application using Burp
Check for NPM modules loaded (things like
define(["exports","../node_modules/@organization-name/package-name/)Check if the organization is registered on
https://www.npmjs.com/If not, register it and create the package name with your malicious code
Here is a detailed guide: https://deephunt3r.medium.com/dependency-confusion-4d675eb36e0f