Dependency confusion is a supply chain attack where an attacker can poison the build process by forcing the build system to retrieve a malicious dependency from somewhere on the internet instead of a legitimate internal dependency. This vulnerability can be exploited by an attacker to gain access to the target organization's internal network.
















