Supply Chain Attack Recon

External recon for software supply-chain attack surface — package-namespace squatting candidates, dependency-confusion vulnerabilities, GitHub Actions injection openings, container image registry exposure, SBOM mining, internal-package-name leakage, and CI/CD configuration exposure. Reconnaissance and identification ONLY — actual package publishing / typosquat attacks are EXTERNAL-OFFENSIVE and require explicit written sign-off because they can affect the entire npm/PyPI ecosystem. Use when the target has a public GitHub org, when their build artifacts/SBOMs are reachable, when their docker images are on Docker Hub/GHCR, or when you find internal package names in their JS bundles.

uphiago 575059d 40.1 KB Updated

File contents

uphiago/recon-skills/tree/main/redteam/supply-chain-attack-recon commit 575059d4da

Frequently asked questions

npx skillmds@latest add uphiago/supply-chain-attack-recon