Researcher Alex Birsan discovered that private package names leaked in public repos could be exploited by uploading identically-named packages with higher version numbers to public registries. He achieved RCE on internal servers at 35+ companies including Apple, Microsoft, PayPal, Tesla, and Uber, collecting over $130K in bug bounties.
Sources: Alex Birsan write-up
PACKAGE_NAME_MISMATCH + PACKAGE_REGISTRY_MISMATCH purpose-built for this attack class
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_NAME_MISMATCH + PACKAGE_REGISTRY_MISMATCH purpose-built for this attack class |
| Socket | Caught | Dependency confusion detection |
| Snyk | Missed | No dependency confusion detection |
| Sonatype (Nexus) | Caught | Nexus Firewall controls repository resolution layer |
| Black Duck | Missed | No dependency confusion detection |
| Endor Labs | Missed | No dependency confusion detection |