spark-common
v1.0.0
Published
Security research — dependency confusion proof-of-concept for responsible disclosure
Readme
spark-common — Dependency Confusion PoC
Summary
This package is a security research proof-of-concept demonstrating a dependency confusion vulnerability in Meta's VS Code extension Meta Spark (SparkAR.spark-ar-studio, 11K+ installs).
The spark-common package name was unregistered on the public npm registry while the extension's package.json depended on:
spark-common: ^1.0.0spark-rpc: ^1.0.0
An attacker could have registered these package names and published malicious packages that execute code during npm install.
This PoC
This package only performs DNS lookups to a researcher-controlled server. No data is exfiltrated, no files are modified, no reverse shells or persistent access is established.
Contact
Researcher: [email protected]
