✳flâneur — a map of the web's best reading
Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies
medium.com · 2,436 words · saved by 1 readers
The Story of a Novel Supply Chain Attack
Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies The Story of a Novel Supply Chain Attack Alex Birsan 11 min read · Feb 9, 2021 -- 57 Listen Share Press enter or click to view image in full size Ever since I started learning how to code, I have been fascinated by the level of trust we put in a simple command like this one: pip install package_name Some programming languages, like Python, come with an easy, more or less official method of installing dependencies for your projects. These installers are usually tied to public code repositories where anyone ca
Explore this link on the map →saved by
related reading
- Fixing the Dependency Confusion Vulnerability in 600+ Ruby Apps - Shopifyshopify.engineering
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- NPM Install Everything, and the Complete and Utter Chaos That Followsboehs.org
- We should all be using dependency cooldownsblog.yossarian.net
- State of DevSecOps | Datadogdatadoghq.com
- The Node-IPC Incidentnotes.ekzhang.com
- Snyk on X: "@karpathy The LiteLLM dependency incident didn't "just happen" though. This is part of a larger campaign LiteLLM already extends to supply chain security fallout for other projects: https://t.co/7bL3kNHP15" / Xx.com
- Defining A Software Supply Chain Security Platform & Exploring New Techniques, Part 2softwareanalyst.substack.com
- Ultralytics AI Library Hacked via GitHub for Cryptomining | Wiz Blogwiz.io
- Security incident disclosure — July 2026huggingface.co
- GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blogwiz.io
- npm left-pad incident - Wikipediaen.wikipedia.org