Why
The PoC reproduces the name-resolution mismatch in a sandbox and the scoping/lockfile defenses, framing the registry as trusted input that is not.
How it works
Not yet built.
Workspace Index › Dev Notes › Dependency confusion — the package manager pulls the wrong registry
#183PoC
Publishing a public package with an internal package's name can make a build fetch the attacker's version, a supply-chain class that hit major companies via npm and PyPI defaults.
The PoC reproduces the name-resolution mismatch in a sandbox and the scoping/lockfile defenses, framing the registry as trusted input that is not.
Not yet built.
내부 패키지 이름으로 공개 패키지를 발행하면 빌드가 공격자 버전을 가져올 수 있으며, npm·PyPI 기본값을 통해 대기업을 강타한 공급망 계급입니다.
이 PoC는 샌드박스에서 이름 해석 불일치와 스코핑/락파일 방어책을 재현하여, 레지스트리를 사실은 아닌데 신뢰되는 입력으로 규정합니다.
아직 만들지 않음.