From DEF CON Research to Automated Supply Chain Defense, finding npx confusion vulnerabilities with npxconfuse
lab.ctbb.show | research | #rce | #supply-chain | #zero-day | #open-source | #mcp | #npm | #npx | #dependency-confusion
Summary
The npxconfuse scanner automates detection of npx confusion and scoped binary name mismatches, finding unclaimed npm package names in codebases and GitHub orgs, including a Brave MCP server zero-day.
- Published
- Collected
Skip to content