Enterprise Dependency Confusion

discovered 2025-01-16

Dependency-confusion packages (SafeDep actor handle sl4x0) that mimic the private/internal package names of specific enterprises (Hyatt, Schedaero, Coca-Cola, Genoma, Anduril, Goldman Sachs and others) and beacon host and environment data out-of-band to attacker-controlled collectors. All publisher accounts use emails on sl4x0.xyz; the npm loader family exfiltrates via dns.resolve4() to oob.sl4x0.xyz. Some waves publish generic (untargeted) install-beacon packages that match no identified enterprise namespace.

Objective

Achieve code execution inside targeted organizations by winning the public/private package name resolution race.

Packages

Indicators

Techniques

Read the full analysis →