Supply Chain Security
Testing for Dependency Confusion and Typosquatting Attacks in Your Supply Chain
In February 2021, security researcher Alex Birsan compromised 35 major companies — including Apple, Microsoft, PayPal, and Tesla — using a technique called dependency confusion. He uploaded malicious packages to public registries with the same names as internal private packages, then watched as the build systems of major corporations automatically downloaded and