Skip to content

lirantal/lockfile-injection-research

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

21 Commits
 
 
 
 

Repository files navigation

Lockfile Injection

This repository is home to the Lockfile Injection research, disclosed in 2019 by Liran Tal.

It was originally published in September 2019 as Why npm lockfiles can be a security blindspot for injecting malicious modules on the Snyk blog.

This open source repository is a continuation of the original research which revealed flaws in popular JavaScript package managers like npm and yarn.

npm Lockfile Injection

npm Lockfile Injection resources:

Tooling:

Ruby Lockfile Injection

Ruby Lockfile Injection articles:

This is unique. I’ve never considered that attack vector before, that someone with access to the codebase could send a PR with a malicious change to the Gemfile.lock but not touch the Gemfile.

Source: reddit discussion

Other media coverage

  • This security research was presented at Blackhat 2021 in a talked titled Picking Lockfiles: Attacking & Defending Your Supply Chain by GitLab security researchers.

image

About

Lockfile injection research

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published