Skip to content

Dependency Confusion

Definition

An attack technique in which an attacker publishes a public package with the same name as an organisation's internal private package at a higher version number. Package managers that check public registries before private ones will download the attacker's version, executing malicious code in the victim's build environment.

Domain
Software supply-chain security
Mechanism
Public package spoofs a private package name
Exploited flaw
Registry resolution order favouring public source
Impact
Malicious code executes in the victim's build

Common questions

How is dependency confusion typically prevented?+

Organisations scope their internal package names to a private namespace, configure package managers to only pull those scoped names from the internal registry, and reserve the matching public package name as a placeholder so an attacker cannot register it.

How is this distinct from typosquatting?+

Typosquatting relies on a developer mistyping a package name, while dependency confusion exploits a legitimate, correctly typed internal package name being resolved against the wrong registry, requiring no typing error by the victim.

Related terms

NIST SP 800-161R1
The US National Institute of Standards and Technology publication 'Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations' (Revision 1, 2022)....
Software Bill of Materials (SBOM)
A structured, machine-readable inventory of the software components in a product or system. Captures component names, versions, licences, and dependency relationships. Standard...
Software Composition Analysis (SCA)
A category of security tooling that scans source code, build manifests, and container images to identify open-source and third-party components, match them...
Transitive Dependency
A software library that an application does not import directly but is pulled in automatically because a direct dependency requires it. Transitive...
Vendor Due Diligence
The pre-procurement and ongoing process of assessing a supplier's security practices before and during a commercial relationship. In supply-chain risk management, due...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.