Skip to main content

supplychain-overview

Supply-chain attack category — dependency confusion, typosquatting, package-registry abuse, build-pipeline poisoning, SBOM manipulation.

معلومات المصدر

المستودع
BitterSecurity/Decepticon
آخر نشاط في المصدر
٢٦ مايو ٢٠٢٦ في ٠٣:١٢
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٥٬٦١١
التفرعات
١٬٠٦١

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.

مستكشف الملفات
2 ملفات

عرض SKILL.md

SKILL.md
تعليمات المصدر · معاينة للقراءة فقط
name
supplychain-overview
description
Supply-chain attack category — dependency confusion, typosquatting, package-registry abuse, build-pipeline poisoning, SBOM manipulation.
allowed-tools
Bash Read Write
metadata
{"subdomain":"supply-chain","when_to_use":"supply chain, dependency confusion, typosquat, package, npm, pypi, rubygems, cargo, maven, gradle, sbom, ci, github actions, build pipeline, registry, vendored","tags":"supply-chain, dependency-confusion, typosquatting, ci-cd","mitre_attack":"T1195, T1195.001, T1195.002"}
# Supply-Chain Exploitation — Category Overview This is a **routing skill** for supply-chain attack research. Sub-skills cover specific techniques against the dependency, build, and distribution layers. ## Sub-Skills | Sub-Skill | Covers | When to Load | |---|---|---| | **dep-confusion** | Public-registry impersonation of private package names, scoped-package abuse (`@org/pkg`), internal-name OSINT (lockfiles, GitHub Actions, Dockerfiles, error pages) | Target uses private npm/PyPI/RubyGems/Cargo registries and you've discovered internal package names in public artifacts | `load_skill("/skills/standard/exploit/supplychain/dep-confusion/SKILL.md")` | ## Surface Discovery ```bash # Lockfiles often expose private package names that aren't on public registry grep -hE '"name":|"@.+/' package-lock.json yarn.lock pnpm-lock.yaml | sort -u # pip grep -E '^[a-z0-9_-]+' requirements.txt # go.mod grep '^\s*[a-z0-9./_-]\+\s' go.mod # Maven grep -A1 '<artifactId>' pom.xml | grep -v '^--$' ``` ## Decision Notes - Always confirm scope authorization in writing before publishing any package, even a benign one, to a public registry. Some bounty programs explicitly disallow public-registry submissions. - Use a beacon-only payload (DNS callback, HTTPS GET) for confirmation; never ship code that mutates the target environment without an explicit follow-up authorization. - Real damage from confusion attacks is usually post-install scripts (`postinstall`, `setup.py install`) — focus PoCs on benign callbacks, not RCE. - For build-pipeline poisoning (workflow injection, branch protection bypass) see `/skills/standard/exploit/ad/SKILL.md` (CI-as-AD-equivalent paths) and the broader threat-modeling under `/skills/shared/opsec/SKILL.md`.
عرض على GitHub