Hacking your infra from the outside by exploiting npm Dependency Confusion attacks

Hacking your infra from the outside by exploiting npm Dependency Confusion attacks


What happens when you incorrectly manage your private packages registry, your developers misconfigure their local npm proxy, and malicious actors are free to abuse an open-source ecosystem? It's called Dependency Confusion and it's an attack that enabled security researchers to infiltrate big-name corps. You don't want to be the next victim on the headlines, right? Let me take you on a step-by-step deep dive into how this attack manifests and how you can defend against it.


Liran Tal

Director of Developer Relations, Snyk

Snyk (スニーク) は、デベロッパーセキュリティプラットフォームです。Snyk は、コードやオープンソースとその依存関係、コンテナや IaC (Infrastructure as a Code) における脆弱性を見つけるだけでなく、優先順位をつけて修正するためのツールです。世界最高峰の脆弱性データベースを基盤に、Snyk の脆弱性に関する専門家としての知見が提供されます。


© 2024 Snyk Limited
Registered in England and Wales
