@selfpentest/bin-confusion
v1.0.1
Published
An example package for training oneself that uses bin confusion to run a script
Readme
bin-confusion

⚠️ Not intended for actual use.
You can use this package to pentest your own applications to see if they are vulnerable to supply chain attacks.
This package demonstrates a supply chain attack where a malicious package is published to the npm registry with a bin field that defines CLI commands colliding with locally installed npm CLI.
The malicious package will be called instead of npm in the project scripts, like:
{
"scripts": {
"test": "npm run lint && npm run unit",
}
}When installed, it will trigger on use of npm in scripts and will demonstrate exfiltrating environment variables and the first 30 characters of .ssh/known_hosts to a server listening on http://localhost:1337/
Use npx @selfpentest/demo-cc to run the local HTTP server that will receive and display the demonstration payload.
Intent
This package is not a hacking tool. It lets the developer check if their setup is vulnerable and can be used for security demonstrations.
