Skip to main content
FOSSA Logo

Dependency Confusion

A software supply chain attack where malicious packages with the same name as internal dependencies are published to public repositories, tricking build systems into using the malicious version.

See your software supply chain in full

FOSSA maps every open source dependency, license, and vulnerability across your codebase, so the terms on this page become findings you can act on.