Skip to main content

supplychain-overview

Supply-chain attack category — dependency confusion, typosquatting, package-registry abuse, build-pipeline poisoning, SBOM manipulation.

Informações da origem

Repositório
BitterSecurity/Decepticon
Última atividade na origem
26 de maio de 2026 às 03:12
Idioma detectado do SKILL.md
inglês
Estrelas
5.611
Forks
1.061

Opções de instalação

Por padrão, está selecionado o prompt que primeiro revisa a origem. Você pode mudar para um comando direto ou baixar uma cópia local.

Revise os arquivos de origem

Leia o SKILL.md e os arquivos complementares exibidos pelo SkillsMP antes de decidir se vai instalar.

Explorador de arquivos
2 arquivos

Exibindo SKILL.md

SKILL.md
Instruções da origem · Visualização somente leitura
name
supplychain-overview
description
Supply-chain attack category — dependency confusion, typosquatting, package-registry abuse, build-pipeline poisoning, SBOM manipulation.
allowed-tools
Bash Read Write
metadata
{"subdomain":"supply-chain","when_to_use":"supply chain, dependency confusion, typosquat, package, npm, pypi, rubygems, cargo, maven, gradle, sbom, ci, github actions, build pipeline, registry, vendored","tags":"supply-chain, dependency-confusion, typosquatting, ci-cd","mitre_attack":"T1195, T1195.001, T1195.002"}
# Supply-Chain Exploitation — Category Overview This is a **routing skill** for supply-chain attack research. Sub-skills cover specific techniques against the dependency, build, and distribution layers. ## Sub-Skills | Sub-Skill | Covers | When to Load | |---|---|---| | **dep-confusion** | Public-registry impersonation of private package names, scoped-package abuse (`@org/pkg`), internal-name OSINT (lockfiles, GitHub Actions, Dockerfiles, error pages) | Target uses private npm/PyPI/RubyGems/Cargo registries and you've discovered internal package names in public artifacts | `load_skill("/skills/standard/exploit/supplychain/dep-confusion/SKILL.md")` | ## Surface Discovery ```bash # Lockfiles often expose private package names that aren't on public registry grep -hE '"name":|"@.+/' package-lock.json yarn.lock pnpm-lock.yaml | sort -u # pip grep -E '^[a-z0-9_-]+' requirements.txt # go.mod grep '^\s*[a-z0-9./_-]\+\s' go.mod # Maven grep -A1 '<artifactId>' pom.xml | grep -v '^--$' ``` ## Decision Notes - Always confirm scope authorization in writing before publishing any package, even a benign one, to a public registry. Some bounty programs explicitly disallow public-registry submissions. - Use a beacon-only payload (DNS callback, HTTPS GET) for confirmation; never ship code that mutates the target environment without an explicit follow-up authorization. - Real damage from confusion attacks is usually post-install scripts (`postinstall`, `setup.py install`) — focus PoCs on benign callbacks, not RCE. - For build-pipeline poisoning (workflow injection, branch protection bypass) see `/skills/standard/exploit/ad/SKILL.md` (CI-as-AD-equivalent paths) and the broader threat-modeling under `/skills/shared/opsec/SKILL.md`.
Ver no GitHub