Habr•September 19, 2026•🇷🇺Translated from Russian

Dependency Confusion Attacks Let Attackers Hijack Internal Library Names in Corporate Builds

A build of an internal library suddenly took minutes instead of seconds and began making unexpected outbound connections. All dependencies were internal and the component had no reason to reach the internet.

Initial suspicion fell on the proxy repository cache, yet its configuration was correct. Investigation revealed that the package manager was querying the company’s own package not only from the internal proxy but also from the public registry because a second source had been added to the settings.

Internal libraries are named with ordinary strings such as billing-common or auth-client. In most ecosystems a package is identified solely by this string; the first party to register the name on the public registry owns it. Because these human-readable names are rarely claimed publicly, they remain available for anyone to take.

When a package with the internal name and a deliberately high version such as 99.0.0 is published, the build system selects it over the legitimate internal version. Alex Birsan proved the attack in February 2021 by collecting internal names from public repositories and error logs, publishing high-version packages under those names, and waiting. The packages reached builds at more than 35 large organizations, including Microsoft, Apple, PayPal, Shopify, Netflix, Tesla and Uber.

Execution occurs at install time. In Python, setup.py runs when a source distribution is built; in npm, lifecycle scripts execute by default. Both run with the build agent’s privileges, granting access to tokens, signing keys and the internal network even if the resulting artifact is never promoted to production.

Effective defenses include using a single internal proxy repository that never mixes public answers for internal names, registering scoped namespaces such as @company and binding them to the private registry, maintaining lock files with content hashes, and disabling install scripts with flags such as --ignore-scripts.

Related articles

Habr•Supply Chain & Open Source

Security Researcher Builds SAST Scanner for AI-Generated Code and Audits 3,800 Public Repositories

A developer released AigisSAST, a lightweight open-source static analysis tool written in pure Python with no external dependencies, specifically tuned to detect common mistakes made by AI coding assistants. The scanner was run across roughly 3,800 repositories ranging from small pet projects to popular open-source platforms. It identified thousands of potential secrets and misconfigurations, yet manual review reduced the number of genuine leaks to approximately 30 cases, mostly Telegram bot tokens, database credentials, and committed .env files. The project also examined 471 production-grade Telegram bots handling payments and VPN services, uncovering 31 repositories that exposed real credentials either in current code or in Git history. AigisSAST includes 21 detection rules, 193 regression tests, automatic remediation via the fix command, and seamless integration with GitHub Actions. The author deliberately avoided validating any discovered keys to stay within ethical research boundaries.

Habr•Supply Chain & Open Source

Vendor Responsibility in Open Source: Licensing Obligations Exposed by Sonatype Nexus Changes

The article examines how vendors building products on copyleft open source projects like Nexus Repository OSS inherit significant legal and security responsibilities under licenses such as EPL 1.0. Sonatype's February 2025 shift from regular OSS binary releases to a limited Community Edition forces downstream vendors to handle their own builds, patch porting, and compliance disclosures. This change highlights the second part of copyleft licenses that outlines obligations for distributors, including revealing modifications and assuming liability for the final product. Security implications arise because critical vulnerabilities in the upstream project must now be tracked and patched by the vendor, with delays creating measurable supply chain risks. The piece provides a practical checklist for buyers to assess licensing hygiene, SBOM availability, and vulnerability response times in any open source-based solution.

AntiMalware•Supply Chain & Open Source

PhantomSub Campaign Deploys 101 Malicious npm Packages to Hijack WhatsApp Accounts for Unauthorized Channel Subscriptions

Researchers at OX Security uncovered 101 malicious npm packages tied to the PhantomSub campaign that abuse connected WhatsApp accounts to subscribe users to promotional channels without consent. The packages disguise themselves as modified versions of the open-source Baileys library used for WhatsApp automation. Attackers rely on authenticated sessions rather than simple package installation, allowing them to control subscriptions through lists stored on GitHub, in plaintext, or as encoded identifiers. The packages have accumulated roughly 490,000 downloads, including 116,000 in the past 30 days, though the exact number of compromised accounts remains unknown. As of 28 September, npm had removed only 16 of the identified packages. The operation ultimately benefits channels selling bots, game resources, accounts, and promotion services by inflating subscriber counts while disabling notifications to hide the activity.

Habr•Supply Chain & Open Source

AI Model Hallucinations Fuel Slopsquatting Attacks on PyPI and npm Registries

Researchers identified 139 package names consistently hallucinated by five different AI models across Python and JavaScript ecosystems. Seven of these names are already registered on PyPI and npm, including one previously used to distribute malware. The attack vector, termed slopsquatting, allows attackers to register AI-suggested package names and execute code with developer privileges during installation. One package, metro-evaluator, contained malicious code removed by npm in December 2025, while another empty package css-color-stop began receiving downloads after the list was published. Real projects such as odf and lusid now occupy names that AI models recommend, causing developers to install unrelated software. Studies show hallucination rates between 4.62% and 21.7% depending on the model, with commercial models performing better than open-source ones. The findings highlight risks when AI coding agents execute dependency installation commands without human verification.