Loading...
AI Dependency Confusion
ADCExploitation of package management systems to inject malicious AI libraries or dependencies into AI development workflows.
Example Scenario
Attacker uploads malicious package "torch-vision" (similar to "torchvision") to PyPI with higher version number, causing automated installs during AI project builds.
Testing Objectives
- Test package resolution mechanisms
- Assess dependency validation
- Evaluate build security controls
- Test package verification systems
Defensive Strategies
- Package pinning and lock files
- Private package repositories
- Dependency scanning tools
- Package signature verification
- Build environment isolation
Key Features
- Package name similarity
- Version number manipulation
- Automated installation triggers
- Credential harvesting capabilities
Use Cases
- Package management security testing
- Dependency validation assessment
- Build pipeline security evaluation
- Developer environment testing
Tools & Frameworks
Security Risks
Ethical Guidelines
- •Only test in isolated development environments
- •Never publish malicious packages to public repositories
- •Report suspicious packages to repository maintainers
- •Focus on improving package security controls
- •Protect the developer ecosystem from supply chain attacks
Remember: This information is for educational and defensive security purposes only. Always ensure you have proper authorization before testing any techniques.
From the engineer behind this catalog
Get your agent system red-teamed
The attacks documented here work on production agent systems every day. Have yours tested before someone else does: prompt injection, jailbreaks, tool misuse and data exfiltration, with every finding written up next to its fix.
€750 instead of €1,500, one week, written report and walkthrough call, until 30 September