What problem does it solve?
External reconnaissance of software supply-chain attack surface to identify dependency-confusion candidates, internal-package-name leakage, GitHub Actions injection openings, container image registry exposure, SBOM mining, and CI/CD configuration exposure. Reconnaissance and identification ONLY; actual publishing or typosquat attacks require explicit written sign-off because they can affect the entire npm/PyPI ecosystem.
Core Features & Use Cases
- Identify package-namespace squatting candidates, dependency-confusion vulnerabilities, GitHub Actions injection openings, container image registry exposure, SBOM mining, internal-package-name leakage, and CI/CD configuration exposure.
- Use when the target has a public GitHub organization, build artifacts/SBOMs are reachable, docker images are on public registries, or internal-looking package names appear in JS bundles.
- Note: External-only boundary; actual publishing or typosquat activities require explicit authorization.
Quick Start
Run an external reconnaissance pass against the target's public GitHub organization to identify dependency-confusion candidates, internal-package-name leakage, SBOM exposure, and CI/CD configuration exposure.